CWE-121: CWE-121

1,029
Total CVEs
201
Critical
703
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 88
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 17
10 Tp Link 17

All CWE-121 CVEs (1,029)

CVE-2024-20688
7.1

This Secure Boot vulnerability allows attackers to bypass security features and potentially execute unauthorized code during the boot process. It affe...

Apr 9, 2024
CVE-2023-21414
7.1

This vulnerability allows attackers to bypass Secure Boot protection on Axis devices, potentially enabling unauthorized firmware modifications or pers...

Oct 16, 2023
CVE-2024-55577
7.0

A stack-based buffer overflow vulnerability in Linux Ratfor 1.06 and earlier allows attackers to execute arbitrary code by providing specially crafted...

Jan 15, 2025
CVE-2024-38246
7.0

This CVE describes a Win32k elevation of privilege vulnerability in Windows systems. It allows an authenticated attacker to execute arbitrary code wit...

Sep 10, 2024
CVE-2025-68622
6.8

A stack buffer overflow vulnerability in Espressif ESP-IDF USB Host UVC Class Driver allows malicious USB cameras to corrupt memory during configurati...

Jan 12, 2026
CVE-2025-60674
6.8

A stack buffer overflow vulnerability in D-Link DIR-878A1 router firmware allows attackers with physical access or control over a USB device to potent...

Nov 13, 2025
CVE-2025-54617
6.8

A stack-based buffer overflow vulnerability in the dms_fwk module allows attackers to execute arbitrary code with system privileges. This affects Huaw...

Aug 6, 2025
CVE-2025-8474
6.8

A stack-based buffer overflow vulnerability in Alpine iLX-507 CarPlay implementation allows physically present attackers to execute arbitrary code as ...

Aug 1, 2025
CVE-2025-5829
6.8

This vulnerability allows physically present attackers to execute arbitrary code on Autel MaxiCharger AC Wallbox Commercial EV chargers by exploiting ...

Jun 25, 2025
CVE-2024-20523
6.8

This vulnerability allows authenticated administrators on Cisco Small Business routers to send crafted HTTP requests that cause the device to unexpect...

Oct 2, 2024
CVE-2024-23933
6.8

A stack-based buffer overflow vulnerability in Sony XAV-AX5500 CarPlay implementation allows physically present attackers to execute arbitrary code wi...

Sep 23, 2024
CVE-2023-51623
6.8

This CVE describes a stack-based buffer overflow in the prog.cgi binary of D-Link DIR-X3260 routers, allowing authenticated, network-adjacent attacker...

May 3, 2024
CVE-2023-51617
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw ex...

May 3, 2024
CVE-2023-51619
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw ex...

May 3, 2024
CVE-2023-51621
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw ex...

May 3, 2024
CVE-2023-51615
6.8

This vulnerability allows network-adjacent attackers with authentication to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw exist...

May 3, 2024
CVE-2023-50225
6.8

This vulnerability allows network-adjacent attackers with authentication to execute arbitrary code as root on TP-Link TL-WR902AC routers. The flaw exi...

May 3, 2024
CVE-2023-41226
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-3040 routers. The flaw exi...

May 3, 2024
CVE-2023-41228
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-3040 routers. The flaw exi...

May 3, 2024
CVE-2023-41219
6.8

This is a stack-based buffer overflow vulnerability in D-Link DIR-3040 routers that allows authenticated attackers on the local network to execute arb...

May 3, 2024
CVE-2023-41221
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-3040 routers. The flaw exi...

May 3, 2024
CVE-2023-41224
6.8

This CVE describes a stack-based buffer overflow vulnerability in D-Link DIR-3040 routers that allows authenticated attackers on the local network to ...

May 3, 2024
CVE-2023-40478
6.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on NETGEAR RAX30 routers by exploiting a stack-based buffer ove...

May 3, 2024
CVE-2023-51631
6.8

This vulnerability allows network-adjacent attackers with valid credentials to execute arbitrary code as root on D-Link DIR-X3260 routers. The flaw ex...

May 2, 2024
CVE-2025-20749
6.7

This CVE describes a buffer overflow vulnerability in MediaTek's charger component that allows local privilege escalation. An attacker with initial Sy...

Nov 4, 2025
CVE-2025-20747
6.7

This vulnerability in the GNSS service allows an out-of-bounds write due to incorrect bounds checking. It enables local privilege escalation if an att...

Nov 4, 2025
CVE-2025-20746
6.7

This vulnerability in the GNSS service allows an attacker with System privilege to perform an out-of-bounds write, potentially leading to local privil...

Nov 4, 2025
CVE-2025-20739
6.7

This vulnerability in MediaTek wlan AP driver allows an attacker with System privilege to perform an out-of-bounds write, potentially leading to local...

Nov 4, 2025
CVE-2025-20738
6.7

This CVE describes an out-of-bounds write vulnerability in MediaTek's wlan AP driver due to incorrect bounds checking. It allows local privilege escal...

Nov 4, 2025
CVE-2025-20736
6.7

This vulnerability in MediaTek wlan AP driver allows local privilege escalation through an out-of-bounds write due to incorrect bounds checking. An at...

Nov 4, 2025
CVE-2023-46718
6.7

This CVE describes a stack-based buffer overflow vulnerability in Fortinet FortiOS that allows attackers to execute arbitrary code or commands via spe...

Oct 14, 2025
CVE-2025-40580
6.7

A stack-based buffer overflow vulnerability in Siemens SCALANCE LPE9403 industrial switches allows local attackers to execute arbitrary code or cause ...

May 13, 2025
CVE-2024-46663
6.7

A stack-buffer overflow vulnerability in Fortinet FortiMail CLI allows privileged attackers to execute arbitrary code or commands via crafted CLI comm...

Mar 11, 2025
CVE-2024-20130
6.7

This CVE describes a memory corruption vulnerability in MediaTek power management components where missing bounds checks allow out-of-bounds writes. A...

Dec 2, 2024
CVE-2024-4550
6.7

A buffer overflow vulnerability in Lenovo ThinkSystem and ThinkStation products allows local attackers with elevated privileges to execute arbitrary c...

Sep 13, 2024
CVE-2026-25727
6.5

This vulnerability in the Rust time crate allows denial of service via stack exhaustion when parsing malicious RFC 2822 date/time strings. It affects ...

Feb 6, 2026
CVE-2026-21903
6.5

A stack-based buffer overflow vulnerability in Juniper Junos OS Packet Forwarding Engine allows authenticated low-privilege attackers to cause denial-...

Jan 15, 2026
CVE-2025-20794
6.5

This vulnerability in MediaTek modems allows improper input validation to cause system crashes, leading to remote denial of service. Attackers can exp...

Jan 6, 2026
CVE-2025-62852
6.5

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modify memory or crash processes. ...

Jan 2, 2026
CVE-2025-53597
6.5

A buffer overflow vulnerability in QNAP License Center allows authenticated administrators to modify memory or crash processes. This affects systems r...

Jan 2, 2026
CVE-2025-53593
6.5

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modify memory or crash processes. ...

Jan 2, 2026
CVE-2025-65804
6.5

This CVE describes a stack overflow vulnerability in Tenda AX3 routers that allows remote attackers to execute arbitrary code by sending specially cra...

Dec 8, 2025
CVE-2025-60699
6.5

This CVE describes a buffer overflow vulnerability in TOTOLINK A950RG router firmware that allows unauthenticated remote attackers to execute arbitrar...

Nov 13, 2025
CVE-2025-60693
6.5

A stack-based buffer overflow vulnerability in Linksys E1200 v2 routers allows remote attackers to execute arbitrary code or cause denial of service w...

Nov 13, 2025
CVE-2025-60684
6.5

A stack buffer overflow vulnerability in ToToLink router firmware allows unauthenticated attackers to execute arbitrary code or cause memory corruptio...

Nov 13, 2025
CVE-2025-60688
6.5

A stack buffer overflow vulnerability in ToToLink router firmware allows unauthenticated attackers to execute arbitrary code or crash devices by sendi...

Nov 13, 2025
CVE-2025-33202
6.5

NVIDIA Triton Inference Server contains a stack overflow vulnerability where attackers can send extra-large payloads to cause denial of service. This ...

Nov 11, 2025
CVE-2023-43683
6.5

A stack buffer out-of-bounds access vulnerability exists in Malwarebytes and Nebula products due to integer underflow when handling newline characters...

Aug 14, 2025
CVE-2025-50464
6.5

A pre-authentication buffer overflow vulnerability in iptime NAS firmware allows attackers to execute arbitrary code by sending specially crafted HTTP...

Jul 30, 2025
CVE-2024-51473
6.5

IBM Db2 database servers are vulnerable to denial of service attacks where a specially crafted query can cause the server to crash. This affects Db2 v...

Jul 29, 2025

About CWE-121 (CWE-121)

Our database tracks 1,029 CVEs classified as CWE-121, with 201 rated critical and 703 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free