CWE-121: CWE-121

1,009
Total CVEs
189
Critical
694
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,009)

CVE-2024-2983
8.8

This critical vulnerability in Tenda FH1202 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formSet...

Mar 27, 2024
CVE-2024-2980
8.8

This critical vulnerability in Tenda FH1202 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formexe...

Mar 27, 2024
CVE-2024-2977
8.8

A critical stack-based buffer overflow vulnerability in Tenda F1203 routers allows remote attackers to execute arbitrary code by manipulating the PPPO...

Mar 27, 2024
CVE-2024-2979
8.8

A critical stack-based buffer overflow vulnerability in Tenda F1203 routers allows remote attackers to execute arbitrary code by manipulating time par...

Mar 27, 2024
CVE-2024-2902
8.8

This is a critical stack-based buffer overflow vulnerability in Tenda AC7 routers that allows remote attackers to execute arbitrary code by manipulati...

Mar 26, 2024
CVE-2024-2900
8.8

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the saveParent...

Mar 26, 2024
CVE-2024-2898
8.8

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the fromSetRou...

Mar 26, 2024
CVE-2024-2895
8.8

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WPS config...

Mar 26, 2024
CVE-2024-2893
8.8

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the device nam...

Mar 26, 2024
CVE-2024-2891
8.8

This critical vulnerability in Tenda AC7 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the PPPOE pass...

Mar 26, 2024
CVE-2024-2855
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the 'time...

Mar 24, 2024
CVE-2024-2852
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the 'urls...

Mar 24, 2024
CVE-2024-2850
8.8

This CVE describes a critical stack-based buffer overflow vulnerability in Tenda AC15 routers. Attackers can remotely exploit this by manipulating the...

Mar 24, 2024
CVE-2024-2815
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the passw...

Mar 22, 2024
CVE-2024-2813
8.8

This critical vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WiFi conf...

Mar 22, 2024
CVE-2024-2811
8.8

This critical vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WPS confi...

Mar 22, 2024
CVE-2024-2809
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the firew...

Mar 22, 2024
CVE-2024-2807
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the fileP...

Mar 22, 2024
CVE-2024-2805
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the speed...

Mar 22, 2024
CVE-2024-2763
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code by manipulating the func...

Mar 21, 2024
CVE-2024-2710
8.8

This critical vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the setSched...

Mar 20, 2024
CVE-2024-2708
8.8

This critical vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formexeC...

Mar 20, 2024
CVE-2024-2705
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code by manipulating the 'lis...

Mar 20, 2024
CVE-2024-2703
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code by manipulating the 'mac...

Mar 20, 2024
CVE-2024-2489
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by manipulating the 'list...

Mar 15, 2024
CVE-2024-2487
8.8

This critical vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formSetDe...

Mar 15, 2024
CVE-2024-2485
8.8

A critical stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by manipulating the speed...

Mar 15, 2024
CVE-2024-27656
8.8

This vulnerability in D-Link DIR-823G routers allows attackers to exploit a buffer overflow via the Cookie parameter. Attackers can cause Denial of Se...

Feb 29, 2024
CVE-2024-25748
8.8

A stack-based buffer overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via the fromSetIpMacBind function. ...

Feb 22, 2024
CVE-2024-0578
8.8

A critical stack-based buffer overflow vulnerability in Totolink LR1200GB routers allows remote attackers to execute arbitrary code by manipulating th...

Jan 16, 2024
CVE-2024-0576
8.8

A critical stack-based buffer overflow vulnerability in Totolink LR1200GB routers allows remote attackers to execute arbitrary code by manipulating th...

Jan 16, 2024
CVE-2024-0575
8.8

CVE-2024-0575 is a critical stack-based buffer overflow vulnerability in Totolink LR1200GB routers that allows remote attackers to execute arbitrary c...

Jan 16, 2024
CVE-2024-0573
8.8

A critical stack-based buffer overflow vulnerability in Totolink LR1200GB routers allows remote attackers to execute arbitrary code by manipulating th...

Jan 16, 2024
CVE-2024-0571
8.8

A critical stack-based buffer overflow vulnerability in Totolink LR1200GB routers allows remote attackers to execute arbitrary code by manipulating th...

Jan 16, 2024
CVE-2024-0541
8.8

A critical stack-based buffer overflow vulnerability exists in Tenda W9 routers running firmware version 1.0.0.7(4456). Attackers can remotely exploit...

Jan 15, 2024
CVE-2024-0538
8.8

A critical stack-based buffer overflow vulnerability in Tenda W9 routers allows remote attackers to execute arbitrary code by manipulating the ssidInd...

Jan 15, 2024
CVE-2024-0536
8.8

A critical stack-based buffer overflow vulnerability in Tenda W9 routers allows remote attackers to execute arbitrary code by manipulating the ssidInd...

Jan 15, 2024
CVE-2023-36006
8.8

This vulnerability allows remote code execution through the Microsoft WDAC OLE DB provider for SQL Server. An attacker could exploit this to execute a...

Dec 12, 2023
CVE-2023-35055
8.8

A buffer overflow vulnerability in the Yifan YF325 router's HTTP server allows remote attackers to execute arbitrary commands by sending specially cra...

Oct 11, 2023
CVE-2023-38148
8.8

CVE-2023-38148 is a stack-based buffer overflow vulnerability in Windows Internet Connection Sharing (ICS) service that allows remote code execution. ...

Sep 12, 2023
CVE-2023-35322
8.8

CVE-2023-35322 is a remote code execution vulnerability in Windows Deployment Services (WDS) that allows an unauthenticated attacker to execute arbitr...

Jul 11, 2023
CVE-2023-24018
8.8

A stack-based buffer overflow vulnerability in the libzebra.so library of Milesight UR32L routers allows authenticated attackers to execute arbitrary ...

Jul 6, 2023
CVE-2023-2575
8.8

This CVE describes a stack-based buffer overflow vulnerability in Advantech EKI-15XX series industrial switches. Authenticated users can exploit it vi...

May 8, 2023
CVE-2023-27355
8.8

This is a critical buffer overflow vulnerability in Sonos One Speaker's MPEG-TS parser that allows network-adjacent attackers to execute arbitrary cod...

Apr 20, 2023
CVE-2022-43622
8.8

This is a critical buffer overflow vulnerability in D-Link DIR-1935 routers that allows network-adjacent attackers to execute arbitrary code as root w...

Mar 29, 2023
CVE-2022-43630
8.8

This is a critical buffer overflow vulnerability in D-Link DIR-1935 routers that allows attackers on the same network to execute arbitrary code as roo...

Mar 29, 2023
CVE-2022-27646
8.8

This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code with root privileges on NETGEAR R6700v3 route...

Mar 29, 2023
CVE-2022-24355
8.8

This vulnerability allows attackers on the same network to execute arbitrary code as root on TP-Link TL-WR940N routers without authentication. It's a ...

Feb 18, 2022
CVE-2021-20046
8.8

A stack-based buffer overflow vulnerability in SonicOS firewalls allows remote authenticated attackers to cause denial of service and potentially exec...

Jan 10, 2022
CVE-2021-34991
8.8

This is a critical buffer overflow vulnerability in NETGEAR R6400v2 routers that allows network-adjacent attackers to execute arbitrary code as root w...

Nov 15, 2021

About CWE-121 (CWE-121)

Our database tracks 1,009 CVEs classified as CWE-121, with 189 rated critical and 694 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free