CWE-121: CWE-121

968
Total CVEs
187
Critical
655
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 33
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 18
9 Debian 16
10 Deltaww 15

All CWE-121 CVEs (968)

CVE-2024-34943
9.8

CVE-2024-34943 is a critical stack-based buffer overflow vulnerability in Tenda FH1206 routers that allows remote attackers to execute arbitrary code ...

May 14, 2024
CVE-2024-29164
9.8

CVE-2024-29164 is a critical stack buffer overflow vulnerability in HDF5 library versions through 1.14.3. Exploitation can corrupt the instruction poi...

May 14, 2024
CVE-2024-33511
9.8

This is a critical buffer overflow vulnerability in Aruba's Automatic Reporting service that allows unauthenticated attackers to execute arbitrary cod...

May 1, 2024
CVE-2024-26304
9.8

This is a critical buffer overflow vulnerability in Aruba's L2/L3 Management service that allows unauthenticated attackers to execute arbitrary code w...

May 1, 2024
CVE-2023-50434
9.8

CVE-2023-50434 is a stack-based buffer over-read vulnerability in emdns's emdns_resolve_raw function that occurs when processing DNS requests. Remote ...

Apr 29, 2024
CVE-2024-33215
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Tenda FH1206 routers. Attackers can exploit this vulnerability by sending s...

Apr 23, 2024
CVE-2024-32318
9.8

This vulnerability in Tenda AC500 routers allows remote attackers to execute arbitrary code via a stack overflow in the VLAN configuration function. A...

Apr 17, 2024
CVE-2024-27683
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in D-Link Go-RT-AC750 routers. Attackers can exploit it by sending a specially...

Apr 11, 2024
CVE-2024-29756
9.8

This CVE describes a buffer overflow vulnerability in the Android audio framework (q6afe.c) that allows local privilege escalation without user intera...

Apr 5, 2024
CVE-2024-30628
9.8

CVE-2024-30628 is a critical stack overflow vulnerability in Tenda FH1205 routers that allows remote attackers to execute arbitrary code by sending sp...

Mar 29, 2024
CVE-2024-30622
9.8

This CVE describes a stack overflow vulnerability in Tenda FH1205 routers that allows remote code execution by sending specially crafted requests to t...

Mar 29, 2024
CVE-2024-30589
9.8

This CVE describes a stack overflow vulnerability in Tenda FH1202 routers that allows remote code execution. Attackers can exploit the 'entrys' parame...

Mar 28, 2024
CVE-2024-30595
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda FH1202 routers by exploiting a stack overflow in the addWifiMacFilter fu...

Mar 28, 2024
CVE-2024-28014
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in multiple NEC Aterm router models that allows remote attackers to execute ar...

Mar 28, 2024
CVE-2023-45924
9.8

This vulnerability in libglvnd's libglxproto.c allows a buffer overflow via glXGetDrawableScreen() function, potentially leading to arbitrary code exe...

Mar 27, 2024
CVE-2024-25393
9.8

A stack buffer overflow vulnerability in RT-Thread's AT command server component allows remote code execution. This affects all systems running RT-Thr...

Mar 27, 2024
CVE-2024-28383
9.8

This vulnerability is a stack overflow in Tenda AX12 routers that allows remote attackers to execute arbitrary code by sending a specially crafted SSI...

Mar 14, 2024
CVE-2024-1783
9.8

A critical stack-based buffer overflow vulnerability in Totolink LR1200GB routers allows remote attackers to execute arbitrary code by manipulating th...

Feb 23, 2024
CVE-2024-0321
9.8

A stack-based buffer overflow vulnerability in GPAC multimedia framework allows attackers to execute arbitrary code or cause denial of service by send...

Jan 8, 2024
CVE-2023-45225
9.8

Multiple Zavio IP camera models with firmware M2.1.6.05 contain stack-based buffer overflow vulnerabilities in XML parsing. Attackers can send special...

Nov 8, 2023
CVE-2023-43755
9.8

Multiple Zavio IP camera models with firmware M2.1.6.05 contain stack-based buffer overflow vulnerabilities in XML parsing. Attackers can send special...

Nov 8, 2023
CVE-2023-3959
9.8

Multiple Zavio IP camera models with firmware M2.1.6.05 contain stack-based buffer overflow vulnerabilities in XML processing. Attackers can send spec...

Nov 8, 2023
CVE-2023-38584
9.8

This vulnerability in Weintek's cMT3000 HMI Web CGI device allows anonymous attackers to exploit a stack-based buffer overflow in the command_wb.cgi c...

Oct 19, 2023
CVE-2023-43492
9.8

This vulnerability in Weintek's cMT3000 HMI Web CGI device allows anonymous attackers to exploit a stack-based buffer overflow in the codesys.cgi comp...

Oct 19, 2023
CVE-2023-34365
9.8

A stack-based buffer overflow vulnerability in Yifan YF325 routers allows remote attackers to execute arbitrary code by sending specially crafted netw...

Oct 11, 2023
CVE-2023-33028
9.8

This vulnerability allows memory corruption in Qualcomm WLAN firmware during PMK cache operations, potentially enabling remote code execution. It affe...

Oct 3, 2023
CVE-2023-2262
9.8

A buffer overflow vulnerability in Rockwell Automation 1756-EN* communication devices allows remote code execution via malicious CIP requests. This af...

Sep 20, 2023
CVE-2023-4744
9.8

This critical vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formSetDev...

Sep 4, 2023
CVE-2023-33308
9.8

A critical stack-based buffer overflow vulnerability in Fortinet FortiOS and FortiProxy allows remote unauthenticated attackers to execute arbitrary c...

Jul 26, 2023
CVE-2023-23902
9.8

A buffer overflow vulnerability in the uhttpd login functionality of Milesight UR32L routers allows remote attackers to execute arbitrary code by send...

Jul 6, 2023
CVE-2023-0855
9.8

A buffer overflow vulnerability in the IPP number-up attribute processing of Canon multifunction printers allows network attackers to crash devices or...

May 11, 2023
CVE-2023-0853
9.8

A buffer overflow vulnerability in the mDNS NSEC record registration process of Canon multifunction printers allows attackers on the same network segm...

May 11, 2023
CVE-2022-2825
9.8

CVE-2022-2825 is a critical buffer overflow vulnerability in Kepware KEPServerEX that allows unauthenticated remote attackers to execute arbitrary cod...

Mar 29, 2023
CVE-2022-23125
9.8

CVE-2022-23125 is a critical stack-based buffer overflow vulnerability in Netatalk's copyapplfile function that allows unauthenticated remote attacker...

Mar 28, 2023
CVE-2022-24673
9.8

CVE-2022-24673 is a critical buffer overflow vulnerability in Canon imageCLASS MF644Cdw printers that allows remote attackers to execute arbitrary cod...

Mar 28, 2023
CVE-2022-0194
9.8

CVE-2022-0194 is a critical stack-based buffer overflow vulnerability in Netatalk's ad_addcomment function that allows unauthenticated remote attacker...

Mar 28, 2023
CVE-2023-20078
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code or cause denial of service on affected Cisco IP Phones through th...

Mar 3, 2023
CVE-2021-42756
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code on FortiWeb web application firewalls via specially craf...

Feb 16, 2023
CVE-2022-33279
9.8

CVE-2022-33279 is a critical stack-based buffer overflow vulnerability in Qualcomm WLAN firmware that allows remote code execution when processing mal...

Feb 12, 2023
CVE-2022-43764
9.8

This vulnerability in B&R APROL Tbase server allows attackers to cause buffer overflow through insufficient input validation when changing configurati...

Feb 8, 2023
CVE-2022-20825
9.8

An unauthenticated remote attacker can execute arbitrary code with root privileges on affected Cisco Small Business routers by sending crafted HTTP re...

Jun 15, 2022
CVE-2022-22274
9.8

CVE-2022-22274 is a critical stack-based buffer overflow vulnerability in SonicOS firewalls that allows remote unauthenticated attackers to trigger de...

Mar 25, 2022
CVE-2022-24049
9.8

This is a critical remote code execution vulnerability in Sonos One Speaker systems that allows unauthenticated attackers to execute arbitrary code as...

Feb 18, 2022
CVE-2021-43299
9.8

CVE-2021-43299 is a critical stack-based buffer overflow vulnerability in the PJSUA API of the pjproject library, triggered when calling pjsua_player_...

Feb 16, 2022
CVE-2021-43301
9.8

This is a critical stack buffer overflow vulnerability in the PJSUA API of pjproject when calling pjsua_playlist_create. An attacker can exploit this ...

Feb 16, 2022
CVE-2021-35003
9.8

This vulnerability allows remote attackers to execute arbitrary code as root on TP-Link Archer C90 routers without authentication. Attackers can explo...

Jan 21, 2022
CVE-2022-22989
9.8

CVE-2022-22989 is a critical pre-authentication stack overflow vulnerability in My Cloud OS 5's FTP service that allows unauthenticated attackers on t...

Jan 13, 2022
CVE-2021-20038
9.8

A stack-based buffer overflow vulnerability in SonicWall SMA 100 series appliances' Apache httpd mod_cgi module allows remote unauthenticated attacker...

Dec 8, 2021
CVE-2021-3064
9.8

This is a critical memory corruption vulnerability in Palo Alto Networks GlobalProtect portal and gateway interfaces that allows unauthenticated attac...

Nov 10, 2021
CVE-2021-38389
9.8

This vulnerability allows remote attackers to execute arbitrary code on Advantech WebAccess systems by exploiting a stack-based buffer overflow. Attac...

Oct 18, 2021

About CWE-121 (CWE-121)

Our database tracks 968 CVEs classified as CWE-121, with 187 rated critical and 655 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free