CWE-121: CWE-121

970
Total CVEs
187
Critical
657
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 33
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 19
9 Debian 16
10 Deltaww 15

All CWE-121 CVEs (970)

CVE-2021-38432
9.8

CVE-2021-38432 is a critical remote code execution vulnerability in FATEK Automation Communication Server. Attackers can exploit improper input valida...

Oct 15, 2021
CVE-2021-38408
9.8

A stack-based buffer overflow vulnerability in Advantech WebAccess allows remote attackers to execute arbitrary code by sending specially crafted data...

Sep 9, 2021
CVE-2021-32943
9.8

This vulnerability allows remote attackers to execute arbitrary code on Advantech WebAccess/SCADA systems via a stack-based buffer overflow. Attackers...

Aug 10, 2021
CVE-2021-1609
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands or code on affected Cisco Small Business VPN routers through ...

Aug 4, 2021
CVE-2021-0276
9.8

A stack-based buffer overflow vulnerability in Juniper Networks SBR Carrier with EAP authentication allows attackers to crash the RADIUS daemon, causi...

Jul 15, 2021
CVE-2021-35474
9.8

A stack-based buffer overflow vulnerability in Apache Traffic Server's cachekey plugin allows remote attackers to execute arbitrary code or cause deni...

Jun 30, 2021
CVE-2021-27480
9.8

Delta Industrial Automation COMMGR versions 1.12 and prior contain a stack-based buffer overflow vulnerability that allows remote attackers to execute...

Apr 27, 2021
CVE-2020-2501
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in QNAP Surveillance Station that allows remote attackers to execute arbitrary...

Feb 17, 2021
CVE-2020-1896
9.8

CVE-2020-1896 is a stack overflow vulnerability in Facebook Hermes JavaScript engine's 'builtin apply' function that could allow remote code execution...

Feb 2, 2021
CVE-2020-27221
9.8

This is a critical stack-based buffer overflow vulnerability in Eclipse OpenJ9 JVM versions up to 0.23. It allows attackers to execute arbitrary code ...

Jan 21, 2021
CVE-2020-25189
9.8

CVE-2020-25189 allows unauthenticated remote attackers to execute arbitrary code on affected IP150 devices via stack-based buffer overflows. This affe...

Nov 21, 2020
CVE-2020-17407
9.8

CVE-2020-17407 is a critical buffer overflow vulnerability in Microhard Bullet-LTE devices that allows unauthenticated remote attackers to execute arb...

Oct 13, 2020
CVE-2023-3043
9.6

This vulnerability in AMI's SPx BMC allows attackers on adjacent networks to trigger a stack-based buffer overflow. Successful exploitation could comp...

Jan 9, 2024
CVE-2023-37293
9.6

This vulnerability in AMI's SPx BMC firmware allows attackers on adjacent networks to trigger a stack-based buffer overflow. Exploitation could lead t...

Jan 9, 2024
CVE-2020-15744
9.6

A stack-based buffer overflow vulnerability in the ONVIF server component of Victure PC420 smart cameras allows remote attackers to execute arbitrary ...

Aug 30, 2021
CVE-2020-14498
9.6

CVE-2020-14498 is a critical stack-based buffer overflow vulnerability in HMS Industrial Networks AB eCatcher software that allows remote attackers to...

Aug 26, 2020
CVE-2021-32941
9.4

This critical vulnerability in Annke N48PBB Network Video Recorders allows remote attackers to execute arbitrary code with root privileges via a stack...

May 23, 2022
CVE-2025-32058
9.3

This vulnerability allows an attacker with code execution on the infotainment system's main processor to execute arbitrary code on the RH850 CAN commu...

Feb 15, 2026
CVE-2024-25331
9.3

This vulnerability allows unauthenticated attackers on the local network to execute arbitrary code on affected D-Link routers by exploiting a buffer o...

Mar 12, 2024
CVE-2023-31029
9.3

This vulnerability allows an unauthenticated attacker to exploit a stack overflow in the NVIDIA DGX A100 BMC's host KVM daemon via a specially crafted...

Jan 12, 2024
CVE-2025-68670
9.1

CVE-2025-68670 is an unauthenticated stack-based buffer overflow vulnerability in xrdp (open source RDP server) that allows remote attackers to execut...

Jan 27, 2026
CVE-2025-61128
9.1

A stack-based buffer overflow vulnerability in WAVLINK router firmware allows attackers to execute arbitrary code by sending a specially crafted HTTP ...

Oct 28, 2025
CVE-2024-39757
9.1

This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers by exploiting a stack-based buffer overflow ...

Jan 14, 2025
CVE-2024-30166
9.1

A malicious client can exploit a stack buffer over-read vulnerability in Mbed TLS 3.3.0 through 3.5.2 to cause information disclosure or denial of ser...

Apr 3, 2024
CVE-2023-33218
9.1

This vulnerability allows remote attackers to execute arbitrary code on affected devices by exploiting a stack buffer overflow in Parameter Zone Read/...

Dec 15, 2023
CVE-2023-33220
9.1

CVE-2023-33220 is a stack-based buffer overflow vulnerability in IDEMIA firmware's retrofit validation process that allows remote code execution. Atta...

Dec 15, 2023
CVE-2021-21887
9.1

This vulnerability allows authenticated remote attackers to execute arbitrary code on Lantronix PremierWave 2050 devices by exploiting a stack-based b...

Dec 22, 2021
CVE-2021-21891
9.1

This vulnerability allows authenticated remote attackers to execute arbitrary code on Lantronix PremierWave 2050 devices by sending a specially crafte...

Dec 22, 2021
CVE-2025-22457
KEV EPSS 55.5% 9.0

A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways allows remote unauthenticated attackers to execu...

Apr 3, 2025
CVE-2025-30472
9.0

Corosync versions through 3.1.9 contain a stack-based buffer overflow vulnerability in the orf_token_endian_convert function when processing large UDP...

Mar 22, 2025
CVE-2025-0282
KEV EPSS 94.1% 9.0

A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways allows remote unauthenticated attack...

Jan 8, 2025
CVE-2024-28038
9.0

This vulnerability allows remote attackers to execute arbitrary code on affected Sharp and Toshiba multifunction printers by sending an overly long MF...

Nov 26, 2024
CVE-2024-34026
9.0

A stack-based buffer overflow vulnerability in OpenPLC Runtime's EtherNet/IP parser allows remote code execution by sending specially crafted EtherNet...

Sep 18, 2024
CVE-2023-50734
9.0

A buffer overflow vulnerability in the PostScript interpreter of Lexmark devices allows attackers to execute arbitrary code by sending specially craft...

Feb 28, 2024
CVE-2023-31024
9.0

This vulnerability in NVIDIA DGX A100 BMC's host KVM daemon allows unauthenticated attackers to cause stack memory corruption via specially crafted ne...

Jan 12, 2024
CVE-2023-41028
9.0

A stack-based buffer overflow vulnerability in Juplink RX4-1500 WiFi routers allows authenticated attackers to execute arbitrary code with root privil...

Aug 23, 2023
CVE-2021-25385
9.0

This vulnerability allows attackers to execute arbitrary code on the mediaextractor process through improper input validation in Samsung's libsdffextr...

Jun 11, 2021
CVE-2023-36998
8.9

CVE-2023-36998 is a stack-based buffer overflow vulnerability in NextEPC MME's Emergency Number List decoding. Attackers with cellphone connections to...

Jan 22, 2025
CVE-2025-32061
8.8

A stack-based buffer overflow in the Alps Alpine Bluetooth stack of Bosch Infotainment ECUs allows remote code execution with root privileges. Attacke...

Feb 15, 2026
CVE-2019-25318
8.8

CVE-2019-25318 is a stack overflow vulnerability in AVS Audio Converter 9.1.2.600 that allows remote code execution when attackers manipulate the outp...

Feb 12, 2026
CVE-2025-66176
8.8

A stack overflow vulnerability in Hikvision Access Control Products allows attackers on the same local network to crash devices by sending specially c...

Jan 13, 2026
CVE-2025-66177
8.8

A stack overflow vulnerability in Hikvision's device Search and Discovery feature allows attackers on the same local network to crash devices by sendi...

Jan 13, 2026
CVE-2025-15273
8.8

A stack-based buffer overflow vulnerability in FontForge's PFB file parser allows remote attackers to execute arbitrary code when users open malicious...

Dec 31, 2025
CVE-2025-60691
8.8

A stack-based buffer overflow vulnerability in Linksys E1200 v2 routers allows remote attackers to execute arbitrary code or cause denial of service w...

Nov 13, 2025
CVE-2025-60690
8.8

A stack-based buffer overflow vulnerability in Linksys E1200 v2 routers allows remote attackers to execute arbitrary code or cause denial of service w...

Nov 13, 2025
CVE-2025-64096
8.8

A stack-based buffer overflow vulnerability in CryptoLib's Crypto_Key_update() function allows remote attackers to trigger memory corruption by sendin...

Oct 30, 2025
CVE-2025-54399
8.8

Multiple stack-based buffer overflow vulnerabilities in Planet WGR-500 routers allow remote code execution via specially crafted HTTP requests. Attack...

Oct 7, 2025
CVE-2025-54401
8.8

Multiple stack-based buffer overflow vulnerabilities in Planet WGR-500 routers allow remote code execution via specially crafted HTTP requests. Attack...

Oct 7, 2025
CVE-2025-8653
8.8

This is a critical stack-based buffer overflow vulnerability in Kenwood DMX958XR's JKRadioService that allows network-adjacent attackers to execute ar...

Aug 6, 2025
CVE-2025-5827
8.8

A stack-based buffer overflow in the ble_process_esp32_msg function of Autel MaxiCharger AC Wallbox Commercial EV chargers allows network-adjacent att...

Jun 25, 2025

About CWE-121 (CWE-121)

Our database tracks 970 CVEs classified as CWE-121, with 187 rated critical and 657 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free