CWE-121: CWE-121
Yearly Trend
Top Affected Vendors
All CWE-121 CVEs (970)
CVE-2021-38432 is a critical remote code execution vulnerability in FATEK Automation Communication Server. Attackers can exploit improper input valida...
Oct 15, 2021A stack-based buffer overflow vulnerability in Advantech WebAccess allows remote attackers to execute arbitrary code by sending specially crafted data...
Sep 9, 2021This vulnerability allows remote attackers to execute arbitrary code on Advantech WebAccess/SCADA systems via a stack-based buffer overflow. Attackers...
Aug 10, 2021This vulnerability allows unauthenticated remote attackers to execute arbitrary commands or code on affected Cisco Small Business VPN routers through ...
Aug 4, 2021A stack-based buffer overflow vulnerability in Juniper Networks SBR Carrier with EAP authentication allows attackers to crash the RADIUS daemon, causi...
Jul 15, 2021A stack-based buffer overflow vulnerability in Apache Traffic Server's cachekey plugin allows remote attackers to execute arbitrary code or cause deni...
Jun 30, 2021Delta Industrial Automation COMMGR versions 1.12 and prior contain a stack-based buffer overflow vulnerability that allows remote attackers to execute...
Apr 27, 2021This CVE describes a critical stack-based buffer overflow vulnerability in QNAP Surveillance Station that allows remote attackers to execute arbitrary...
Feb 17, 2021CVE-2020-1896 is a stack overflow vulnerability in Facebook Hermes JavaScript engine's 'builtin apply' function that could allow remote code execution...
Feb 2, 2021This is a critical stack-based buffer overflow vulnerability in Eclipse OpenJ9 JVM versions up to 0.23. It allows attackers to execute arbitrary code ...
Jan 21, 2021CVE-2020-25189 allows unauthenticated remote attackers to execute arbitrary code on affected IP150 devices via stack-based buffer overflows. This affe...
Nov 21, 2020CVE-2020-17407 is a critical buffer overflow vulnerability in Microhard Bullet-LTE devices that allows unauthenticated remote attackers to execute arb...
Oct 13, 2020This vulnerability in AMI's SPx BMC allows attackers on adjacent networks to trigger a stack-based buffer overflow. Successful exploitation could comp...
Jan 9, 2024This vulnerability in AMI's SPx BMC firmware allows attackers on adjacent networks to trigger a stack-based buffer overflow. Exploitation could lead t...
Jan 9, 2024A stack-based buffer overflow vulnerability in the ONVIF server component of Victure PC420 smart cameras allows remote attackers to execute arbitrary ...
Aug 30, 2021CVE-2020-14498 is a critical stack-based buffer overflow vulnerability in HMS Industrial Networks AB eCatcher software that allows remote attackers to...
Aug 26, 2020This critical vulnerability in Annke N48PBB Network Video Recorders allows remote attackers to execute arbitrary code with root privileges via a stack...
May 23, 2022This vulnerability allows an attacker with code execution on the infotainment system's main processor to execute arbitrary code on the RH850 CAN commu...
Feb 15, 2026This vulnerability allows unauthenticated attackers on the local network to execute arbitrary code on affected D-Link routers by exploiting a buffer o...
Mar 12, 2024This vulnerability allows an unauthenticated attacker to exploit a stack overflow in the NVIDIA DGX A100 BMC's host KVM daemon via a specially crafted...
Jan 12, 2024CVE-2025-68670 is an unauthenticated stack-based buffer overflow vulnerability in xrdp (open source RDP server) that allows remote attackers to execut...
Jan 27, 2026A stack-based buffer overflow vulnerability in WAVLINK router firmware allows attackers to execute arbitrary code by sending a specially crafted HTTP ...
Oct 28, 2025This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers by exploiting a stack-based buffer overflow ...
Jan 14, 2025A malicious client can exploit a stack buffer over-read vulnerability in Mbed TLS 3.3.0 through 3.5.2 to cause information disclosure or denial of ser...
Apr 3, 2024This vulnerability allows remote attackers to execute arbitrary code on affected devices by exploiting a stack buffer overflow in Parameter Zone Read/...
Dec 15, 2023CVE-2023-33220 is a stack-based buffer overflow vulnerability in IDEMIA firmware's retrofit validation process that allows remote code execution. Atta...
Dec 15, 2023This vulnerability allows authenticated remote attackers to execute arbitrary code on Lantronix PremierWave 2050 devices by exploiting a stack-based b...
Dec 22, 2021This vulnerability allows authenticated remote attackers to execute arbitrary code on Lantronix PremierWave 2050 devices by sending a specially crafte...
Dec 22, 2021A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways allows remote unauthenticated attackers to execu...
Apr 3, 2025Corosync versions through 3.1.9 contain a stack-based buffer overflow vulnerability in the orf_token_endian_convert function when processing large UDP...
Mar 22, 2025A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways allows remote unauthenticated attack...
Jan 8, 2025This vulnerability allows remote attackers to execute arbitrary code on affected Sharp and Toshiba multifunction printers by sending an overly long MF...
Nov 26, 2024A stack-based buffer overflow vulnerability in OpenPLC Runtime's EtherNet/IP parser allows remote code execution by sending specially crafted EtherNet...
Sep 18, 2024A buffer overflow vulnerability in the PostScript interpreter of Lexmark devices allows attackers to execute arbitrary code by sending specially craft...
Feb 28, 2024This vulnerability in NVIDIA DGX A100 BMC's host KVM daemon allows unauthenticated attackers to cause stack memory corruption via specially crafted ne...
Jan 12, 2024A stack-based buffer overflow vulnerability in Juplink RX4-1500 WiFi routers allows authenticated attackers to execute arbitrary code with root privil...
Aug 23, 2023This vulnerability allows attackers to execute arbitrary code on the mediaextractor process through improper input validation in Samsung's libsdffextr...
Jun 11, 2021CVE-2023-36998 is a stack-based buffer overflow vulnerability in NextEPC MME's Emergency Number List decoding. Attackers with cellphone connections to...
Jan 22, 2025A stack-based buffer overflow in the Alps Alpine Bluetooth stack of Bosch Infotainment ECUs allows remote code execution with root privileges. Attacke...
Feb 15, 2026CVE-2019-25318 is a stack overflow vulnerability in AVS Audio Converter 9.1.2.600 that allows remote code execution when attackers manipulate the outp...
Feb 12, 2026A stack overflow vulnerability in Hikvision Access Control Products allows attackers on the same local network to crash devices by sending specially c...
Jan 13, 2026A stack overflow vulnerability in Hikvision's device Search and Discovery feature allows attackers on the same local network to crash devices by sendi...
Jan 13, 2026A stack-based buffer overflow vulnerability in FontForge's PFB file parser allows remote attackers to execute arbitrary code when users open malicious...
Dec 31, 2025A stack-based buffer overflow vulnerability in Linksys E1200 v2 routers allows remote attackers to execute arbitrary code or cause denial of service w...
Nov 13, 2025A stack-based buffer overflow vulnerability in Linksys E1200 v2 routers allows remote attackers to execute arbitrary code or cause denial of service w...
Nov 13, 2025A stack-based buffer overflow vulnerability in CryptoLib's Crypto_Key_update() function allows remote attackers to trigger memory corruption by sendin...
Oct 30, 2025Multiple stack-based buffer overflow vulnerabilities in Planet WGR-500 routers allow remote code execution via specially crafted HTTP requests. Attack...
Oct 7, 2025Multiple stack-based buffer overflow vulnerabilities in Planet WGR-500 routers allow remote code execution via specially crafted HTTP requests. Attack...
Oct 7, 2025This is a critical stack-based buffer overflow vulnerability in Kenwood DMX958XR's JKRadioService that allows network-adjacent attackers to execute ar...
Aug 6, 2025A stack-based buffer overflow in the ble_process_esp32_msg function of Autel MaxiCharger AC Wallbox Commercial EV chargers allows network-adjacent att...
Jun 25, 2025About CWE-121 (CWE-121)
Our database tracks 970 CVEs classified as CWE-121, with 187 rated critical and 657 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.
External reference: View CWE-121 on MITRE CWE →
Monitor CWE-121 Vulnerabilities
Get alerted when new CWE-121 CVEs affect your infrastructure.
Start Monitoring Free