CWE-121: CWE-121

1,029
Total CVEs
201
Critical
703
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 88
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 17
10 Tp Link 17

All CWE-121 CVEs (1,029)

CVE-2025-53173
5.3

A stack overflow vulnerability exists in Huawei's file preview function when parsing vector images. This could allow attackers to crash the preview se...

Jul 7, 2025
CVE-2024-33516
5.3

An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol in ArubaOS. This allows attackers t...

May 1, 2024
CVE-2024-33518
5.3

An unauthenticated Denial-of-Service vulnerability in Aruba's Radio Frequency Manager service allows attackers to disrupt service operation via the PA...

May 1, 2024
CVE-2024-33514
5.3

Unauthenticated attackers can cause Denial-of-Service (DoS) in Aruba's AP Management service via the PAPI protocol, disrupting network operations. Thi...

May 1, 2024
CVE-2023-1646
5.3

A critical stack-based buffer overflow vulnerability exists in IObit Malware Fighter's IMFCameraProtect.sys driver. Local attackers can exploit this v...

Mar 26, 2023
CVE-2025-60685
5.1

A stack buffer overflow vulnerability in ToToLink A720R router firmware allows attackers with filesystem write access to execute arbitrary code by cra...

Nov 13, 2025
CVE-2025-60686
5.1

This vulnerability allows local attackers to trigger stack-based buffer overflows in ToToLink router firmware by manipulating ARP table data. Attacker...

Nov 13, 2025
CVE-2026-0399
4.9

This CVE describes post-authentication stack-based buffer overflow vulnerabilities in SonicOS management interfaces. Attackers with valid credentials ...

Feb 24, 2026
CVE-2024-47909
4.9

A stack-based buffer overflow vulnerability in Ivanti Connect Secure and Policy Secure allows remote authenticated administrators to cause denial of s...

Nov 12, 2024
CVE-2025-45375
4.4

A stack-based buffer overflow vulnerability in Dell PowerProtect Data Domain with DD OS allows high-privileged attackers with local access to cause de...

Oct 7, 2025
CVE-2025-43374
4.3

This vulnerability allows an attacker in physical proximity to cause an out-of-bounds read in kernel memory on Apple devices. It affects multiple Appl...

Nov 21, 2025
CVE-2025-65220
4.3

A buffer overflow vulnerability in Tenda AC21 routers allows attackers to execute arbitrary code or crash the device by sending specially crafted requ...

Nov 20, 2025
CVE-2025-65221
4.3

Tenda AC21 router firmware version V16.03.08.16 contains a buffer overflow vulnerability in the setPptpUserList function. Attackers can exploit this b...

Nov 20, 2025
CVE-2025-65222
4.3

Tenda AC21 router firmware version V16.03.08.16 contains a buffer overflow vulnerability in the rebootTime parameter of the /goform/SetSysAutoRebbotCf...

Nov 20, 2025
CVE-2025-65223
4.3

A buffer overflow vulnerability exists in Tenda AC21 routers version V16.03.08.16 via the urls parameter in the /goform/saveParentControlInfo endpoint...

Nov 20, 2025
CVE-2025-59801
4.3

A stack-based buffer overflow vulnerability exists in Artifex GhostXPS when processing TIFF files due to insufficient validation of the samplesperpixe...

Sep 22, 2025
CVE-2025-59799
4.3

This CVE describes a stack-based buffer overflow vulnerability in Artifex Ghostscript's PDF processing component. Attackers could exploit this by prov...

Sep 22, 2025
CVE-2024-43032
4.3

CVE-2024-43032 is an authentication bypass vulnerability in autMan v2.9.6 that allows attackers to gain unauthorized access by sending specially craft...

Aug 23, 2024
CVE-2024-40722
4.3

This vulnerability allows unauthenticated remote attackers to cause a stack-based buffer overflow in TCBServiSign Windows software by exploiting impro...

Aug 2, 2024
CVE-2025-55095
4.2

This vulnerability allows a malicious USB storage device to cause a stack overflow by exploiting unlimited recursion in partition table parsing. Syste...

Jan 27, 2026
CVE-2025-24328
4.2

A stack overflow vulnerability in Nokia Single RAN baseband OAM service allows attackers to cause service restarts by sending crafted SOAP messages. T...

Jul 2, 2025
CVE-2025-9820
4.0

A stack buffer overflow vulnerability in GnuTLS's PKCS#11 token initialization function allows writing past buffer boundaries when processing overly l...

Jan 26, 2026
CVE-2025-53175
4.0

A stack overflow vulnerability exists in Huawei products when parsing vector images during file preview. This could allow attackers to crash the previ...

Jul 7, 2025
CVE-2025-53171
4.0

This CVE describes a stack overflow vulnerability in vector image parsing during file preview operations. Attackers could potentially execute arbitrar...

Jul 7, 2025
CVE-2024-58116
4.0

A buffer overflow vulnerability exists in the SVG parsing module of Huawei's ArkUI framework. Successful exploitation could cause denial of service by...

Apr 7, 2025
CVE-2026-27821
N/A

A stack buffer overflow vulnerability in GPAC multimedia framework allows attackers to execute arbitrary code or crash applications by providing malic...

Feb 26, 2026
CVE-2025-26386
N/A

Johnson Controls iSTAR Configuration Utility (ICU) versions 6.9.7 and earlier contain a stack-based buffer overflow vulnerability (CWE-121). This coul...

Jan 28, 2026
CVE-2025-34457
N/A

A stack-based buffer overflow vulnerability in Dire Wolf's KISS frame processing allows remote unauthenticated attackers to cause denial-of-service th...

Dec 22, 2025
CVE-2025-59365
N/A

A stack buffer overflow vulnerability in certain ASUS router models allows authenticated attackers to send crafted requests that could crash the devic...

Nov 25, 2025

About CWE-121 (CWE-121)

Our database tracks 1,029 CVEs classified as CWE-121, with 201 rated critical and 703 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free