CWE-121: CWE-121

1,029
Total CVEs
201
Critical
703
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 88
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 17
10 Tp Link 17

All CWE-121 CVEs (1,029)

CVE-2025-52081
6.5

A stack-based buffer overflow vulnerability in Netgear XR300 routers allows attackers to execute arbitrary code or crash the device by sending special...

Jul 15, 2025
CVE-2025-44172
6.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers by exploiting a stack overflow in the setSmartPowerManagemen...

Jun 2, 2025
CVE-2024-49350
6.5

IBM Db2 databases running vulnerable versions can be crashed by sending specially crafted queries, causing denial of service. This affects Db2 11.1.0-...

May 29, 2025
CVE-2025-44895
6.5

This CVE describes a stack overflow vulnerability in the FW-WGS-804HPT router's web interface. Attackers can exploit this by sending specially crafted...

May 21, 2025
CVE-2025-45862
6.5

This CVE describes a buffer overflow vulnerability in TOTOLINK A3002R routers via the interfacenameds parameter in the formDhcpv6s interface. Attacker...

May 20, 2025
CVE-2025-45847
6.5

This vulnerability allows authenticated attackers to execute arbitrary code on ALFA AIP-W512 routers via a stack overflow in the formWsc function. Att...

May 8, 2025
CVE-2025-44900
6.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda RX3 routers by exploiting a stack overflow in the GetParentControlInfo f...

May 6, 2025
CVE-2025-29218
6.5

Tenda W18E v2.0 router firmware version 16.01.0.11 contains a stack overflow vulnerability in the wifiPwd parameter at /goform/setModules endpoint. At...

Mar 20, 2025
CVE-2025-25634
6.5

A stack-based buffer overflow vulnerability exists in Tenda AC15 routers version 15.03.05.19. Attackers can exploit this by sending specially crafted ...

Mar 5, 2025
CVE-2024-20521
6.5

This vulnerability allows authenticated administrators on affected Cisco Small Business routers to execute arbitrary code with root privileges by send...

Oct 2, 2024
CVE-2024-20519
6.5

This vulnerability allows authenticated administrators on affected Cisco Small Business routers to execute arbitrary code with root privileges by send...

Oct 2, 2024
CVE-2024-9284
6.5

This critical vulnerability in TP-LINK TL-WR841ND routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the w...

Sep 27, 2024
CVE-2024-40417
6.5

A stack-based buffer overflow vulnerability exists in Tenda AX1806 routers running firmware version 1.0.0.1. Attackers can exploit this by sending spe...

Jul 10, 2024
CVE-2024-6402
6.5

This critical vulnerability in Tenda A301 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the fromSetWi...

Jun 28, 2024
CVE-2024-45062
6.4

A stack-based buffer overflow vulnerability in OpenPrinting ippusbxd 1.34 allows arbitrary code execution when a malicious IPP-over-USB printer is con...

Aug 19, 2025
CVE-2025-32766
6.4

A stack-based buffer overflow vulnerability in Fortinet FortiWeb CLI allows privileged attackers to execute arbitrary code or commands via crafted CLI...

Aug 12, 2025
CVE-2024-21758
6.4

A stack-based buffer overflow vulnerability in Fortinet FortiWeb allows privileged users to execute arbitrary code via specially crafted CLI commands....

Jan 14, 2025
CVE-2020-9253
6.3

A stack overflow vulnerability in certain Huawei smartphones allows attackers to craft specific packets to exploit insufficient input validation. Succ...

Dec 27, 2024
CVE-2024-8408
6.3

A critical stack-based buffer overflow vulnerability in Linksys WRT54G routers allows remote attackers to execute arbitrary code by sending specially ...

Sep 4, 2024
CVE-2022-32502
6.3

This vulnerability allows remote attackers to execute arbitrary code on Nuki Bridge devices via a buffer overflow in the encrypted token parsing logic...

May 14, 2024
CVE-2019-25437
6.2

CVE-2019-25437 is a buffer overflow vulnerability in Foscam Video Management System version 1.1.6.6 that allows local attackers to crash the applicati...

Feb 20, 2026
CVE-2019-25334
6.2

CVE-2019-25334 is a local denial-of-service vulnerability in Product Key Explorer 4.2.0.0 where attackers can crash the application by pasting special...

Feb 12, 2026
CVE-2025-12464
6.2

A stack-based buffer overflow vulnerability in QEMU's e1000 network device allows malicious guest users to crash the QEMU process on the host via loop...

Oct 31, 2025
CVE-2025-58300
6.2

A buffer overflow vulnerability in Huawei device management modules allows attackers to crash systems or potentially execute arbitrary code by sending...

Oct 11, 2025
CVE-2025-58301
6.2

A buffer overflow vulnerability in Huawei device management modules could allow attackers to crash affected systems, causing denial of service. This a...

Oct 11, 2025
CVE-2025-59149
6.2

A stack buffer overflow vulnerability in Suricata versions 8.0.0 allows attackers to potentially execute arbitrary code or cause denial of service. Th...

Oct 1, 2025
CVE-2024-29421
6.2

This vulnerability in xmedcon allows attackers to execute arbitrary code via a buffer overflow in the DICOM parsing component. It affects users of xme...

May 22, 2024
CVE-2025-12143
6.1

A stack-based buffer overflow vulnerability in ABB Terra AC wallbox charging stations allows attackers to execute arbitrary code or cause denial of se...

Nov 28, 2025
CVE-2024-41166
6.1

A stack-based buffer overflow vulnerability in Intel PROSet/Wireless WiFi and Killer WiFi software for Windows allows unauthenticated attackers on the...

Feb 12, 2025
CVE-2025-0373
6.0

A stack buffer overflow vulnerability in FreeBSD's cd9660, tarfs, and ext2fs filesystems allows attackers to cause kernel panics on NFS servers export...

Jan 30, 2025
CVE-2025-40843
5.9

CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library when executing the 'log' command. This coul...

Oct 28, 2025
CVE-2025-58295
5.9

A buffer overflow vulnerability in Huawei's development framework module could allow attackers to crash affected systems, potentially causing denial o...

Oct 11, 2025
CVE-2025-58297
5.9

A buffer overflow vulnerability in Huawei sensor service could allow attackers to crash the service or potentially execute arbitrary code. This affect...

Oct 11, 2025
CVE-2025-25896
5.7

A buffer overflow vulnerability in D-Link DSL-3782 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted packets. Thi...

Feb 18, 2025
CVE-2025-25892
5.7

A buffer overflow vulnerability in D-Link DSL-3782 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted packets cont...

Feb 18, 2025
CVE-2025-70309
5.5

A stack overflow vulnerability in GPAC's pcmreframe_flush_packet function allows attackers to cause denial of service by processing a specially crafte...

Jan 15, 2026
CVE-2025-70305
5.5

A stack overflow vulnerability in GPAC's dmx_saf function allows attackers to cause Denial of Service (DoS) by providing a specially crafted .saf file...

Jan 15, 2026
CVE-2023-53879
5.5

NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field. Attackers can crash the application by pasting a ...

Dec 15, 2025
CVE-2025-8404
5.5

This CVE describes a stack buffer overflow vulnerability in Supermicro BMC shared libraries that allows authenticated attackers to execute arbitrary c...

Nov 18, 2025
CVE-2025-25740
5.5

This CVE describes a stack-based buffer overflow vulnerability in D-Link DIR-853 A1 routers via the PSK parameter in the QuickVPN settings module. Att...

Feb 14, 2025
CVE-2024-46325
5.5

TP-Link WR740N V6 routers have a stack overflow vulnerability in the web interface's site survey page. Attackers can exploit this by sending specially...

Oct 7, 2024
CVE-2026-26269
5.4

A stack buffer overflow vulnerability in Vim's NetBeans integration allows remote code execution when processing malicious specialKeys commands. This ...

Feb 13, 2026
CVE-2025-7623
5.4

This vulnerability allows authenticated attackers with SSH access to the BMC to execute arbitrary code via a stack buffer overflow in the SMASH-CLP sh...

Nov 18, 2025
CVE-2025-7704
5.4

This vulnerability allows attackers to execute arbitrary code on Supermicro BMC systems by exploiting a stack-based buffer overflow in the Insyde SMAS...

Nov 13, 2025
CVE-2025-45867
5.4

This CVE describes a buffer overflow vulnerability in TOTOLINK A3002R routers via the static_dns1 parameter in the formIpv6Setup interface. Attackers ...

May 13, 2025
CVE-2020-12820
5.4

A stack-based buffer overflow vulnerability in FortiOS SSL VPN under non-default configurations allows authenticated remote attackers to crash the For...

Dec 19, 2024
CVE-2025-20732
5.3

A buffer overflow vulnerability in MediaTek Wi-Fi AP drivers allows local privilege escalation when an attacker already has system-level access. This ...

Nov 4, 2025
CVE-2025-55117
5.3

A stack-based buffer overflow vulnerability in Control-M/Agent allows remote attackers to potentially execute arbitrary code or crash the service when...

Sep 16, 2025
CVE-2025-57217
5.3

This CVE describes a stack buffer overflow vulnerability in Tenda AC10 routers that allows remote attackers to execute arbitrary code via the Password...

Aug 28, 2025
CVE-2025-51082
5.3

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers by exploiting a stack-based buffer overflow in the web int...

Jul 24, 2025

About CWE-121 (CWE-121)

Our database tracks 1,029 CVEs classified as CWE-121, with 201 rated critical and 703 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free