CWE-121: CWE-121

1,007
Total CVEs
188
Critical
693
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,007)

CVE-2024-4495
8.8

A critical stack-based buffer overflow vulnerability in Tenda i21 routers allows remote attackers to execute arbitrary code by manipulating the index ...

May 5, 2024
CVE-2024-4493
8.8

A critical stack-based buffer overflow vulnerability in Tenda i21 routers allows remote attackers to execute arbitrary code by manipulating ping param...

May 5, 2024
CVE-2024-4492
8.8

A critical stack-based buffer overflow vulnerability in Tenda i21 routers allows remote attackers to execute arbitrary code by manipulating the GO/ssi...

May 5, 2024
CVE-2024-4491
8.8

A critical stack-based buffer overflow vulnerability in Tenda i21 routers allows remote attackers to execute arbitrary code by sending specially craft...

May 5, 2024
CVE-2023-51624
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DCS-8300LHV2 IP cameras without authentication. The f...

May 3, 2024
CVE-2023-51626
8.8

This vulnerability allows attackers on the same network to execute arbitrary code as root on D-Link DCS-8300LHV2 IP cameras without authentication. Th...

May 3, 2024
CVE-2023-50211
8.8

This vulnerability allows attackers on the same network to execute arbitrary code as root on D-Link G416 routers without authentication. The flaw exis...

May 3, 2024
CVE-2023-50209
8.8

This vulnerability allows attackers on the same network to execute arbitrary code as root on D-Link G416 wireless routers without authentication. The ...

May 3, 2024
CVE-2023-50186
8.8

A stack-based buffer overflow vulnerability in GStreamer's AV1 video parser allows remote attackers to execute arbitrary code by crafting malicious AV...

May 3, 2024
CVE-2023-44445
8.8

This is a critical stack-based buffer overflow vulnerability in NETGEAR CAX30 routers that allows network-adjacent attackers to execute arbitrary code...

May 3, 2024
CVE-2023-44417
8.8

This is a critical stack-based buffer overflow vulnerability in D-Link DAP-2622 routers that allows network-adjacent attackers to execute arbitrary co...

May 3, 2024
CVE-2023-44419
8.8

This is a critical unauthenticated remote code execution vulnerability in D-Link DIR-X3260 routers. Network-adjacent attackers can exploit a stack buf...

May 3, 2024
CVE-2023-44409
8.8

A stack-based buffer overflow vulnerability in D-Link DAP-1325 routers allows network-adjacent attackers to execute arbitrary code as root without aut...

May 3, 2024
CVE-2023-44405
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-44407
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-41215
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-41209
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-41211
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-41213
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-41203
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-41205
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-41207
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-40476
8.8

A stack-based buffer overflow vulnerability in GStreamer's H.265 video parsing allows remote attackers to execute arbitrary code by providing speciall...

May 3, 2024
CVE-2023-37320
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. It is caused...

May 3, 2024
CVE-2023-37322
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-37324
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication by exploiting...

May 3, 2024
CVE-2023-37314
8.8

This is a critical stack-based buffer overflow vulnerability in D-Link DAP-2622 routers that allows network-adjacent attackers to execute arbitrary co...

May 3, 2024
CVE-2023-37316
8.8

This is a critical stack-based buffer overflow vulnerability in D-Link DAP-2622 routers that allows network-adjacent attackers to execute arbitrary co...

May 3, 2024
CVE-2023-37318
8.8

This is a critical buffer overflow vulnerability in D-Link DAP-2622 routers that allows network-adjacent attackers to execute arbitrary code as root w...

May 3, 2024
CVE-2023-35755
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-37310
8.8

This is a critical unauthenticated remote code execution vulnerability in D-Link DAP-2622 routers. Network-adjacent attackers can exploit a stack-base...

May 3, 2024
CVE-2023-37312
8.8

This is a critical remote code execution vulnerability in D-Link DAP-2622 routers where network-adjacent attackers can execute arbitrary code as root ...

May 3, 2024
CVE-2023-35747
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35751
8.8

This is a critical stack-based buffer overflow vulnerability in D-Link DAP-2622 routers that allows network-adjacent attackers to execute arbitrary co...

May 3, 2024
CVE-2023-35753
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35741
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35743
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35745
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35735
8.8

This is a critical stack-based buffer overflow vulnerability in D-Link DAP-2622 routers that allows network-adjacent attackers to execute arbitrary co...

May 3, 2024
CVE-2023-35737
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35739
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35729
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35731
8.8

This vulnerability allows attackers on the same network to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw ...

May 3, 2024
CVE-2023-35733
8.8

This is a critical stack-based buffer overflow vulnerability in D-Link DAP-2622 routers that allows network-adjacent attackers to execute arbitrary co...

May 3, 2024
CVE-2023-35725
8.8

This is a critical stack-based buffer overflow vulnerability in D-Link DAP-2622 routers that allows network-adjacent attackers to execute arbitrary co...

May 3, 2024
CVE-2023-35727
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-35718
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-2622 routers without authentication. The buffer o...

May 3, 2024
CVE-2023-34285
8.8

This is a critical stack-based buffer overflow vulnerability in NETGEAR RAX30 routers that allows network-adjacent attackers to execute arbitrary code...

May 3, 2024
CVE-2023-32136
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1360 routers without authentication. Attackers ca...

May 3, 2024
CVE-2023-27368
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code on NETGEAR RAX30 routers without authentication. Attackers can exploit ...

May 3, 2024

About CWE-121 (CWE-121)

Our database tracks 1,007 CVEs classified as CWE-121, with 188 rated critical and 693 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free