CWE-121: CWE-121

972
Total CVEs
187
Critical
659
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 33
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 19
9 Debian 16
10 Deltaww 15

All CWE-121 CVEs (972)

CVE-2025-3887
8.8

A stack-based buffer overflow vulnerability in GStreamer's H265 codec parser allows remote attackers to execute arbitrary code by sending specially cr...

May 22, 2025
CVE-2025-29840
8.8

A stack-based buffer overflow vulnerability in Windows Media allows remote attackers to execute arbitrary code on affected systems. This affects Windo...

May 13, 2025
CVE-2025-27481
8.8

A stack-based buffer overflow vulnerability in Windows Telephony Service allows remote attackers to execute arbitrary code without authentication. Thi...

Apr 8, 2025
CVE-2025-2837
8.8

A stack-based buffer overflow vulnerability in Silicon Labs Gecko OS HTTP request handling allows network-adjacent attackers to execute arbitrary code...

Mar 26, 2025
CVE-2023-46272
8.8

A buffer overflow vulnerability in Extreme Networks IQ Engine's ah_auth service allows attackers to execute arbitrary code on affected systems. This a...

Feb 19, 2025
CVE-2025-25745
8.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-853 A1 routers by exploiting a stack-based buffer overflow in the Q...

Feb 14, 2025
CVE-2025-0438
8.8

A stack buffer overflow vulnerability in Google Chrome's Tracing component allows remote attackers to potentially execute arbitrary code or cause deni...

Jan 15, 2025
CVE-2024-20154
EPSS 57.3% 8.8

This vulnerability allows remote code execution on affected mobile devices when they connect to a malicious rogue base station. Attackers can exploit ...

Jan 6, 2025
CVE-2023-51635
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on NETGEAR RAX30 routers without authentication. The flaw exist...

Nov 22, 2024
CVE-2024-10698
8.8

This critical vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the device nam...

Nov 2, 2024
CVE-2024-10661
8.8

This critical vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the DLNA conf...

Nov 1, 2024
CVE-2024-10434
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary code by manipulating the 'ar...

Oct 28, 2024
CVE-2024-10351
8.8

A critical stack-based buffer overflow vulnerability in Tenda RX9 Pro routers allows remote attackers to execute arbitrary code by sending specially c...

Oct 25, 2024
CVE-2024-10282
8.8

A critical stack-based buffer overflow vulnerability in Tenda RX9 and RX9 Pro routers allows remote attackers to execute arbitrary code by sending spe...

Oct 23, 2024
CVE-2024-10281
8.8

A critical stack-based buffer overflow vulnerability in Tenda RX9 and RX9 Pro routers allows remote attackers to execute arbitrary code by manipulatin...

Oct 23, 2024
CVE-2024-10194
8.8

A critical stack-based buffer overflow vulnerability in WAVLINK routers allows attackers to execute arbitrary code by manipulating the wlanUrl paramet...

Oct 20, 2024
CVE-2024-10130
8.8

This critical vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the reboot tim...

Oct 18, 2024
CVE-2024-10123
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the 'time'...

Oct 18, 2024
CVE-2024-43549
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) by sending sp...

Oct 8, 2024
CVE-2024-23938
8.8

A stack-based buffer overflow in Silicon Labs Gecko OS debug interface allows network-adjacent attackers to execute arbitrary code without authenticat...

Sep 28, 2024
CVE-2024-23934
8.8

A stack-based buffer overflow vulnerability in Sony XAV-AX5500 devices allows remote attackers to execute arbitrary code by tricking users into openin...

Sep 23, 2024
CVE-2024-44589
8.8

A stack overflow vulnerability in the HNAP service login function of D-Link DCS-960L IP cameras allows remote attackers to execute arbitrary code by s...

Sep 18, 2024
CVE-2024-8230
8.8

This critical vulnerability in Tenda O6 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the fromSafeSet...

Aug 28, 2024
CVE-2024-8226
8.8

This critical vulnerability in Tenda O1 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formSetCfm ...

Aug 28, 2024
CVE-2024-8228
8.8

A critical stack-based buffer overflow vulnerability in Tenda O5 routers allows remote attackers to execute arbitrary code by manipulating parameters ...

Aug 28, 2024
CVE-2024-8224
8.8

This critical vulnerability in Tenda G3 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formSetDebu...

Aug 27, 2024
CVE-2024-7908
8.8

This critical vulnerability in TOTOLINK EX1200L routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the set...

Aug 18, 2024
CVE-2024-7707
8.8

This critical vulnerability in Tenda FH1206 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formSaf...

Aug 13, 2024
CVE-2024-7614
8.8

This critical vulnerability in Tenda FH1206 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the QoS con...

Aug 12, 2024
CVE-2024-7581
8.8

This critical vulnerability in Tenda A301 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WiFi conf...

Aug 7, 2024
CVE-2024-7441
8.8

This critical vulnerability in Vivotek SD9364 VVTK-0103f allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the HT...

Aug 3, 2024
CVE-2024-7439
8.8

A critical stack-based buffer overflow vulnerability exists in Vivotek CC8160 VVTK-0100d's httpd component. Attackers can remotely exploit this by man...

Aug 3, 2024
CVE-2024-7151
8.8

This critical vulnerability in Tenda O3 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the MAC filter ...

Jul 27, 2024
CVE-2024-6964
8.8

A critical stack-based buffer overflow vulnerability in Tenda O3 firmware allows remote attackers to execute arbitrary code by manipulating DHCP serve...

Jul 22, 2024
CVE-2024-6962
8.8

A critical stack-based buffer overflow vulnerability in Tenda O3 routers allows remote attackers to execute arbitrary code by manipulating QoS setting...

Jul 22, 2024
CVE-2024-41281
8.8

The Linksys WRT54G router version 4.21.5 contains a stack overflow vulnerability in the get_merge_mac function. This allows attackers to execute arbit...

Jul 19, 2024
CVE-2024-33181
8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers via a stack-based buffer overflow in the addWifiMacFilter f...

Jul 16, 2024
CVE-2024-28899
8.8

This vulnerability allows attackers to bypass Secure Boot protections on affected systems, potentially enabling them to load and execute unauthorized ...

Jul 9, 2024
CVE-2024-6189
8.8

A critical stack-based buffer overflow vulnerability in Tenda A301 routers allows remote attackers to execute arbitrary code by manipulating the wpaps...

Jun 20, 2024
CVE-2024-6144
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code on Actiontec WCB6200Q routers without authentication. The flaw exists i...

Jun 19, 2024
CVE-2024-6146
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code on Actiontec WCB6200Q routers without authentication. The flaw exists i...

Jun 19, 2024
CVE-2024-37641
8.8

This vulnerability allows remote attackers to execute arbitrary code on TRENDnet TEW-814DAP wireless access points via a stack overflow in the formNew...

Jun 14, 2024
CVE-2024-37645
8.8

This vulnerability allows remote attackers to execute arbitrary code on TRENDnet TEW-814DAP wireless access points by exploiting a stack overflow in t...

Jun 14, 2024
CVE-2024-37640
8.8

This vulnerability is a stack overflow in the TOTOLINK A3700R router's setWiFiEasyGuestCfg function, allowing remote attackers to execute arbitrary co...

Jun 14, 2024
CVE-2024-0444
8.8

A stack-based buffer overflow vulnerability in GStreamer's AV1 video parser allows remote attackers to execute arbitrary code by providing specially c...

Jun 7, 2024
CVE-2024-35388
8.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK NR1800X routers via a stack overflow in the urldecode function's pass...

May 24, 2024
CVE-2023-35749
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 7, 2024
CVE-2021-34982
8.8

This is a critical stack-based buffer overflow vulnerability in NETGEAR routers' httpd service that allows network-adjacent attackers to execute arbit...

May 7, 2024
CVE-2024-4497
8.8

This critical vulnerability in Tenda i21 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formexeCom...

May 5, 2024
CVE-2024-4495
8.8

A critical stack-based buffer overflow vulnerability in Tenda i21 routers allows remote attackers to execute arbitrary code by manipulating the index ...

May 5, 2024

About CWE-121 (CWE-121)

Our database tracks 972 CVEs classified as CWE-121, with 187 rated critical and 659 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free