CWE-121: CWE-121

949
Total CVEs
187
Critical
636
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Totolink 30
4 Adobe 25
5 Microsoft 24
6 Milesight 24
7 Siemens 18
8 Cisco 18
9 Debian 16
10 Deltaww 15

All CWE-121 CVEs (949)

CVE-2024-45162
9.8

A stack-based buffer overflow vulnerability in the phddns client of Blu-Castle BCUM221E devices allows remote attackers to execute arbitrary code by s...

Oct 29, 2025
CVE-2025-57085
9.8

This vulnerability in Tenda W30E routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests that trigger a stac...

Sep 9, 2025
CVE-2025-40795
9.8

A stack-based buffer overflow vulnerability in Siemens SIMATIC PCS neo's User Management Component allows unauthenticated remote attackers to execute ...

Sep 9, 2025
CVE-2025-54493
9.8

A critical stack-based buffer overflow vulnerability in libbiosig's MFER parsing allows arbitrary code execution when processing malicious MFER files....

Aug 25, 2025
CVE-2025-54489
9.8

A stack-based buffer overflow vulnerability in libbiosig's MFER parsing allows arbitrary code execution when processing malicious MFER files. This aff...

Aug 25, 2025
CVE-2025-54491
9.8

A critical stack-based buffer overflow vulnerability in libbiosig's MFER parsing allows arbitrary code execution when processing malicious MFER files....

Aug 25, 2025
CVE-2025-54483
9.8

A critical stack-based buffer overflow vulnerability in libbiosig's MFER file parser allows arbitrary code execution when processing malicious MFER fi...

Aug 25, 2025
CVE-2025-54485
9.8

A critical stack-based buffer overflow vulnerability in libbiosig's MFER parsing allows arbitrary code execution when processing malicious MFER files....

Aug 25, 2025
CVE-2025-54487
9.8

A critical stack-based buffer overflow vulnerability in libbiosig's MFER parsing allows arbitrary code execution when processing malicious MFER files....

Aug 25, 2025
CVE-2025-54481
9.8

A stack-based buffer overflow vulnerability in libbiosig's MFER parsing allows arbitrary code execution when processing malicious MFER files. This aff...

Aug 25, 2025
CVE-2010-20113
EPSS 62.7% 9.8

This vulnerability allows remote attackers to execute arbitrary code on EasyFTP Server by exploiting a stack-based buffer overflow in the HTTP interfa...

Aug 21, 2025
CVE-2010-20121
EPSS 68.6% 9.8

EasyFTP Server versions up to 1.7.0.11 contain a critical stack-based buffer overflow vulnerability in the CWD command parser that allows unauthentica...

Aug 21, 2025
CVE-2012-10060
EPSS 69.1% 9.8

CVE-2012-10060 is a critical stack-based buffer overflow vulnerability in Sysax Multi Server's SSH service. Attackers can exploit this by sending an o...

Aug 13, 2025
CVE-2025-23310
9.8

CVE-2025-23310 is a critical stack buffer overflow vulnerability in NVIDIA Triton Inference Server that allows attackers to execute arbitrary code rem...

Aug 6, 2025
CVE-2012-10021
EPSS 55.3% 9.8

This CVE describes a critical stack-based buffer overflow vulnerability in D-Link DIR-605L routers that allows remote unauthenticated attackers to exe...

Jul 31, 2025
CVE-2025-41687
9.8

An unauthenticated remote attacker can exploit a stack-based buffer overflow in the u-link Management API to execute arbitrary code and gain full cont...

Jul 23, 2025
CVE-2025-7921
9.8

This critical vulnerability affects certain Askey modem models, allowing unauthenticated remote attackers to exploit a stack-based buffer overflow to ...

Jul 21, 2025
CVE-2024-25176
9.8

This CVE describes a stack buffer overflow vulnerability in LuaJIT's string formatting function (lj_strfmt_wfnum). Attackers can exploit this to execu...

Jul 7, 2025
CVE-2025-3484
9.8

This critical vulnerability in MedDream PACS Server allows remote attackers to execute arbitrary code without authentication by sending specially craf...

May 22, 2025
CVE-2025-44883
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected FW-WGS-804HPT devices via a stack overflow in the web interface. Atta...

May 20, 2025
CVE-2025-44894
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected FW-WGS-804HPT devices via a stack overflow in the RADIUS server confi...

May 20, 2025
CVE-2025-44897
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected FW-WGS-804HPT devices by exploiting a stack overflow in the web upgra...

May 20, 2025
CVE-2025-44885
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected FW-WGS-804HPT devices by exploiting a stack overflow in the SNMPv3 co...

May 20, 2025
CVE-2025-44887
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected FW-WGS-804HPT devices via a stack overflow in the web_radiusSrv_post ...

May 20, 2025
CVE-2025-44890
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected FW-WGS-804HPT devices via a stack overflow in the SNMP notification c...

May 20, 2025
CVE-2025-45513
9.8

Tenda FH451 router firmware version V1.0.0.9 contains a stack overflow vulnerability in the P2pListFilter function. This allows remote attackers to ex...

May 9, 2025
CVE-2025-3714
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code on LCD KVM over IP Switch CL5708IM devices by exploiting...

May 9, 2025
CVE-2025-3710
9.8

CVE-2025-3710 is a critical stack-based buffer overflow vulnerability in LCD KVM over IP Switch CL5708IM firmware that allows unauthenticated remote a...

May 9, 2025
CVE-2025-45427
9.8

This CVE describes a stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code. The vulnerability affec...

Apr 23, 2025
CVE-2025-42599
KEV 9.8

CVE-2025-42599 is a critical stack-based buffer overflow vulnerability in Active! mail 6 that allows remote unauthenticated attackers to execute arbit...

Apr 18, 2025
CVE-2025-22900
9.8

This vulnerability allows remote attackers to execute arbitrary code on Totolink N600R routers by exploiting a stack overflow in the setWanConfig func...

Apr 15, 2025
CVE-2024-54808
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Netgear WNR854T routers that allows remote attackers to execute arbitrary c...

Mar 31, 2025
CVE-2025-29100
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8 routers via a buffer overflow in the fromSetRouteStatic function. At...

Mar 24, 2025
CVE-2025-2263
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Sante PACS Server systems by exploiting a stack-based buffer o...

Mar 13, 2025
CVE-2024-51138
9.8

A critical stack-based buffer overflow vulnerability in DrayTek router TR069 STUN server URL parsing allows remote attackers to execute arbitrary code...

Feb 27, 2025
CVE-2025-26506
9.8

This vulnerability allows attackers to execute arbitrary code with elevated privileges on affected HP printers by sending malicious PostScript print j...

Feb 14, 2025
CVE-2024-50694
9.8

This vulnerability allows remote attackers to execute arbitrary code on SunGrow WiNet-SV200 devices by exploiting a stack-based buffer overflow when p...

Jan 24, 2025
CVE-2024-48871
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected systems by sending a specially crafted HTTP request t...

Dec 6, 2024
CVE-2024-52544
9.8

An unauthenticated attacker can remotely execute arbitrary code on Lorex 2K Indoor Wi-Fi Security Cameras by exploiting a stack-based buffer overflow ...

Dec 3, 2024
CVE-2024-43689
9.8

A stack-based buffer overflow vulnerability in ELECOM wireless access points allows remote attackers to execute arbitrary code by sending specially cr...

Oct 21, 2024
CVE-2024-45414
9.8

This critical vulnerability in ZTE routers allows unauthenticated remote attackers to execute arbitrary code as root via a stack-based buffer overflow...

Sep 16, 2024
CVE-2024-45694
9.8

This critical vulnerability in D-Link wireless routers allows unauthenticated remote attackers to execute arbitrary code via a stack-based buffer over...

Sep 16, 2024
CVE-2024-45158
9.8

A stack buffer overflow vulnerability in Mbed TLS 3.6 allows attackers to execute arbitrary code or cause denial of service when applications directly...

Sep 5, 2024
CVE-2024-40535
9.8

This vulnerability allows remote attackers to execute arbitrary code on Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 devices by exploiting a sta...

Jul 16, 2024
CVE-2024-36435
9.8

An unauthenticated stack buffer overflow vulnerability in Supermicro BMC firmware allows remote attackers to execute arbitrary code on affected Basebo...

Jul 11, 2024
CVE-2024-35387
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK LR350 routers by exploiting a stack overflow in the loginAuth functio...

May 24, 2024
CVE-2024-35580
9.8

CVE-2024-35580 is a critical stack buffer overflow vulnerability in Tenda AX1806 routers that allows remote attackers to execute arbitrary code or cau...

May 20, 2024
CVE-2024-31469
9.8

CVE-2024-31469 is a critical buffer overflow vulnerability in Aruba's Central Communications service that allows unauthenticated attackers to execute ...

May 14, 2024
CVE-2024-31467
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specia...

May 14, 2024
CVE-2024-31466
9.8

CVE-2024-31466 is a critical buffer overflow vulnerability in Aruba's Access Point management protocol (PAPI) that allows unauthenticated attackers to...

May 14, 2024

About CWE-121 (CWE-121)

Our database tracks 949 CVEs classified as CWE-121, with 187 rated critical and 636 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free