CWE-121: CWE-121

1,015
Total CVEs
192
Critical
697
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,015)

CVE-2021-1322
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Feb 4, 2021
CVE-2021-1324
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1326
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Feb 4, 2021
CVE-2021-1307
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Jan 13, 2021
CVE-2021-1360
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1214
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1216
7.2

Multiple input validation vulnerabilities in Cisco Small Business routers allow authenticated attackers to execute arbitrary code as root or cause den...

Jan 13, 2021
CVE-2021-1202
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1204
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1206
7.2

This vulnerability allows authenticated attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business router...

Jan 13, 2021
CVE-2021-1208
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Jan 13, 2021
CVE-2021-1210
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1212
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1190
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1192
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1194
7.2

Multiple input validation vulnerabilities in Cisco Small Business RV series routers allow authenticated remote attackers to execute arbitrary code as ...

Jan 13, 2021
CVE-2021-1196
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1198
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Jan 13, 2021
CVE-2021-1200
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1175
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1177
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1179
7.2

This vulnerability allows authenticated attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business router...

Jan 13, 2021
CVE-2021-1181
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1183
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1185
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1187
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1161
7.2

Multiple input validation vulnerabilities in Cisco Small Business routers allow authenticated attackers to execute arbitrary code as root or cause den...

Jan 13, 2021
CVE-2021-1163
7.2

Multiple buffer overflow vulnerabilities in Cisco Small Business RV series routers allow authenticated remote attackers to execute arbitrary code as r...

Jan 13, 2021
CVE-2021-1165
7.2

This vulnerability allows authenticated attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business router...

Jan 13, 2021
CVE-2021-1167
7.2

This CVE describes multiple input validation vulnerabilities in Cisco Small Business RV series routers' web management interface. Authenticated attack...

Jan 13, 2021
CVE-2021-1169
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1171
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1173
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root or cause denial of service on affected Cisco Small Business...

Jan 13, 2021
CVE-2021-1159
7.2

This vulnerability allows authenticated attackers with administrator credentials to execute arbitrary code as root or cause denial of service on affec...

Jan 13, 2021
CVE-2023-41217
7.1

This vulnerability allows network-adjacent attackers with authentication to execute arbitrary code as root on D-Link DIR-3040 routers. The flaw exists...

May 3, 2024
CVE-2024-20688
7.1

This Secure Boot vulnerability allows attackers to bypass security features and potentially execute unauthorized code during the boot process. It affe...

Apr 9, 2024
CVE-2023-21414
7.1

This vulnerability allows attackers to bypass Secure Boot protection on Axis devices, potentially enabling unauthorized firmware modifications or pers...

Oct 16, 2023
CVE-2024-55577
7.0

A stack-based buffer overflow vulnerability in Linux Ratfor 1.06 and earlier allows attackers to execute arbitrary code by providing specially crafted...

Jan 15, 2025
CVE-2024-38246
7.0

This CVE describes a Win32k elevation of privilege vulnerability in Windows systems. It allows an authenticated attacker to execute arbitrary code wit...

Sep 10, 2024
CVE-2025-68622
6.8

A stack buffer overflow vulnerability in Espressif ESP-IDF USB Host UVC Class Driver allows malicious USB cameras to corrupt memory during configurati...

Jan 12, 2026
CVE-2025-60674
6.8

A stack buffer overflow vulnerability in D-Link DIR-878A1 router firmware allows attackers with physical access or control over a USB device to potent...

Nov 13, 2025
CVE-2025-54617
6.8

A stack-based buffer overflow vulnerability in the dms_fwk module allows attackers to execute arbitrary code with system privileges. This affects Huaw...

Aug 6, 2025
CVE-2025-8474
6.8

A stack-based buffer overflow vulnerability in Alpine iLX-507 CarPlay implementation allows physically present attackers to execute arbitrary code as ...

Aug 1, 2025
CVE-2025-5829
6.8

This vulnerability allows physically present attackers to execute arbitrary code on Autel MaxiCharger AC Wallbox Commercial EV chargers by exploiting ...

Jun 25, 2025
CVE-2024-20523
6.8

This vulnerability allows authenticated administrators on Cisco Small Business routers to send crafted HTTP requests that cause the device to unexpect...

Oct 2, 2024
CVE-2024-23933
6.8

A stack-based buffer overflow vulnerability in Sony XAV-AX5500 CarPlay implementation allows physically present attackers to execute arbitrary code wi...

Sep 23, 2024
CVE-2023-51623
6.8

This CVE describes a stack-based buffer overflow in the prog.cgi binary of D-Link DIR-X3260 routers, allowing authenticated, network-adjacent attacker...

May 3, 2024
CVE-2023-51617
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw ex...

May 3, 2024
CVE-2023-51619
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw ex...

May 3, 2024
CVE-2023-51621
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw ex...

May 3, 2024

About CWE-121 (CWE-121)

Our database tracks 1,015 CVEs classified as CWE-121, with 192 rated critical and 697 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free