CWE-121: CWE-121

1,009
Total CVEs
189
Critical
694
High
8.1
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
90
2025
277
2024
388
2023
94
2022
42

Top Affected Vendors

1 Tenda 187
2 Dlink 87
3 Cisco 64
4 Totolink 30
5 Adobe 25
6 Microsoft 24
7 Milesight 24
8 Siemens 21
9 Deltaww 16
10 Debian 16

All CWE-121 CVEs (1,009)

CVE-2021-34861
8.8

This is a critical buffer overflow vulnerability in D-Link DAP-2020 routers that allows network-adjacent attackers to execute arbitrary code as root w...

Oct 25, 2021
CVE-2021-34863
8.8

CVE-2021-34863 is a buffer overflow vulnerability in D-Link DAP-2020 routers that allows network-adjacent attackers to execute arbitrary code as root ...

Oct 25, 2021
CVE-2021-34830
8.8

This is a stack-based buffer overflow vulnerability in D-Link DAP-1330 routers that allows network-adjacent attackers to execute arbitrary code withou...

Jul 15, 2021
CVE-2021-31420
8.8

This is a local privilege escalation vulnerability in Parallels Desktop's Toolgate component. Attackers with low-privileged access to a guest VM can e...

Apr 29, 2021
CVE-2021-27248
8.8

This is a critical buffer overflow vulnerability in D-Link DAP-2020 access points that allows network-adjacent attackers to execute arbitrary code as ...

Apr 14, 2021
CVE-2021-27239
8.8

This vulnerability allows attackers on the same network to execute arbitrary code as root on NETGEAR R6400 and R6700 routers without authentication. T...

Mar 29, 2021
CVE-2021-25667
8.8

A stack-based buffer overflow vulnerability in Siemens industrial network devices allows remote attackers to cause denial-of-service or potentially ex...

Mar 15, 2021
CVE-2020-27261
8.8

CVE-2020-27261 is a stack-based buffer overflow vulnerability in Omron CX-One industrial automation software that allows remote attackers to execute a...

Feb 9, 2021
CVE-2020-25177
8.8

A stack-based buffer overflow vulnerability in WECON PLC Editor versions 1.3.8 and earlier allows attackers to execute arbitrary code by sending speci...

Dec 1, 2020
CVE-2026-1761
8.6

A stack-based buffer overflow vulnerability in libsoup allows remote attackers to execute arbitrary code or crash applications by sending specially cr...

Feb 2, 2026
CVE-2026-0719
8.6

This vulnerability in libsoup's NTLM authentication handling allows attackers to cause denial-of-service crashes by sending extremely long passwords t...

Jan 8, 2026
CVE-2025-53418
8.6

Delta Electronics COMMGR software contains a stack-based buffer overflow vulnerability (CWE-121) that allows attackers to execute arbitrary code or ca...

Aug 26, 2025
CVE-2025-51087
8.6

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers by exploiting a stack-based buffer overflow in the savePar...

Jul 24, 2025
CVE-2024-20433
8.6

An unauthenticated remote attacker can send specially crafted RSVP packets to vulnerable Cisco devices, causing a buffer overflow that forces the devi...

Sep 25, 2024
CVE-2024-39950
8.6

This vulnerability in Dahua products allows attackers to send specially crafted packets to vulnerable interfaces, triggering device initialization/res...

Jul 31, 2024
CVE-2021-1573
8.6

An unauthenticated remote attacker can send a malicious HTTPS request to Cisco ASA or FTD devices, causing them to reload and creating a denial of ser...

Jan 11, 2022
CVE-2021-40118
8.6

An unauthenticated remote attacker can send a malicious HTTPS request to Cisco ASA/FTD devices to trigger a denial of service condition, causing the d...

Oct 27, 2021
CVE-2019-25357
8.4

Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field. Attackers can exploit this...

Feb 18, 2026
CVE-2019-25336
8.4

CVE-2019-25336 is a local buffer overflow vulnerability in SpotAuditor's Base64 Encrypted Password tool that allows attackers to execute arbitrary cod...

Feb 12, 2026
CVE-2019-25332
8.4

CVE-2019-25332 is a local stack overflow vulnerability in FTP Commander Pro that allows attackers to execute arbitrary code by overwriting the EIP reg...

Feb 12, 2026
CVE-2026-24882
8.4

A stack-based buffer overflow vulnerability in GnuPG's tpm2daemon component allows attackers to execute arbitrary code or cause denial of service when...

Jan 27, 2026
CVE-2021-47881
8.4

This vulnerability in dataSIMS Avionics ARINC 664-1 version 4.5.3 allows attackers to execute arbitrary code on Windows systems by exploiting a local ...

Jan 23, 2026
CVE-2025-60692
8.4

A stack-based buffer overflow vulnerability in Cisco Linksys E1200 v2 routers allows local attackers to corrupt memory, cause denial of service, or po...

Nov 13, 2025
CVE-2025-60696
8.4

A stack-based buffer overflow vulnerability in Linksys RE7000 routers allows local attackers to cause denial of service or potentially execute arbitra...

Nov 13, 2025
CVE-2019-16641
8.4

This vulnerability allows attackers to bypass authentication on Ruijie EG-2000 series gateways via a buffer overflow in client.so. Attackers can log i...

Jul 16, 2024
CVE-2024-37984
8.4

This vulnerability allows attackers to bypass Secure Boot protections on affected systems, potentially enabling them to load and execute unauthorized ...

Jul 9, 2024
CVE-2024-36600
8.4

A buffer overflow vulnerability in libcdio 2.2.0 allows attackers to execute arbitrary code by providing a maliciously crafted ISO 9660 image file. Th...

Jun 14, 2024
CVE-2024-35333
8.4

A stack buffer overflow vulnerability in html2xhtml 1.3 allows attackers to execute arbitrary code or cause denial of service by providing specially c...

May 29, 2024
CVE-2024-21474
8.4

This CVE describes a memory corruption vulnerability in Qualcomm components where a buffer size from a previous function call is reused without proper...

May 6, 2024
CVE-2024-28580
8.4

A buffer overflow vulnerability in FreeImage v3.19.0 allows local attackers to execute arbitrary code by exploiting the ReadData() function when proce...

Mar 20, 2024
CVE-2024-28582
8.4

A buffer overflow vulnerability in FreeImage v3.19.0 allows local attackers to execute arbitrary code by exploiting the rgbe_RGBEToFloat() function wh...

Mar 20, 2024
CVE-2024-28566
8.4

A buffer overflow vulnerability in FreeImage v3.19.0 allows local attackers to execute arbitrary code by exploiting the AssignPixel() function when pr...

Mar 20, 2024
CVE-2023-28538
8.4

This vulnerability allows memory corruption in Qualcomm WIN Product's UEFI region when invoking the WinAcpi update driver. Attackers could exploit thi...

Sep 5, 2023
CVE-2025-26336
8.3

A stack-based buffer overflow vulnerability in Dell Chassis Management Controller firmware allows unauthenticated remote attackers to execute arbitrar...

Mar 21, 2025
CVE-2023-5055
8.3

CVE-2023-5055 is a stack-based buffer overflow vulnerability in the le_ecred_reconf_req function of Zephyr RTOS Bluetooth LE stack. This allows attack...

Nov 21, 2023
CVE-2020-10064
8.3

This vulnerability allows attackers to execute arbitrary code or cause denial of service via improper input validation in IEEE 802.15.4 frame processi...

May 25, 2021
CVE-2025-4425
8.2

This is a stack-based buffer overflow vulnerability (CWE-121) affecting Lenovo products, allowing attackers to execute arbitrary code or cause denial ...

Jul 30, 2025
CVE-2025-23388
8.2

A stack-based buffer overflow vulnerability in SUSE Rancher allows attackers to cause denial of service by crashing the application. This affects Ranc...

Apr 11, 2025
CVE-2024-1220
8.2

A stack-based buffer overflow vulnerability in the built-in web server of Moxa NPort W2150A/W2250A Series devices allows remote attackers to send craf...

Mar 6, 2024
CVE-2026-24881
8.1

This vulnerability in GnuPG allows attackers to trigger a stack-based buffer overflow by sending specially crafted CMS/S-MIME messages with oversized ...

Jan 27, 2026
CVE-2024-35279
8.1

A stack-based buffer overflow vulnerability in Fortinet FortiOS allows remote unauthenticated attackers to execute arbitrary code via crafted UDP pack...

Feb 11, 2025
CVE-2025-25066
8.1

CVE-2025-25066 is a stack-based buffer overflow vulnerability in nDPI's address cache restoration function. This could allow attackers to execute arbi...

Feb 3, 2025
CVE-2024-53703
8.1

A stack-based buffer overflow vulnerability in SonicWall SMA100 SSLVPN firmware's mod_httprp library allows remote attackers to potentially execute ar...

Dec 5, 2024
CVE-2024-45318
8.1

A stack-based buffer overflow vulnerability in SonicWall SMA100 SSLVPN web management interface allows remote attackers to execute arbitrary code on a...

Dec 5, 2024
CVE-2024-45413
8.1

This vulnerability allows authenticated attackers to execute arbitrary code as root on affected ZTE routers through a stack-based buffer overflow in t...

Sep 16, 2024
CVE-2024-36728
8.1

TRENDnet TEW-827DRU routers contain a stack-based buffer overflow vulnerability in the ssi binary. Authenticated attackers can exploit this by sending...

Jun 3, 2024
CVE-2024-33599
8.1

A stack-based buffer overflow vulnerability in nscd (Name Service Cache Daemon) allows attackers to execute arbitrary code or crash the service when n...

May 6, 2024
CVE-2023-5403
8.1

This vulnerability allows attackers to manipulate server hostname-to-IP address translation, potentially enabling remote code execution or service dis...

Apr 17, 2024
CVE-2023-48266
8.1

This CVE describes a stack-based buffer overflow vulnerability in Bosch products that allows unauthenticated remote attackers to cause denial-of-servi...

Jan 10, 2024
CVE-2023-48262
8.1

This vulnerability in Bosch products allows unauthenticated remote attackers to cause denial-of-service or potentially execute arbitrary code via spec...

Jan 10, 2024

About CWE-121 (CWE-121)

Our database tracks 1,009 CVEs classified as CWE-121, with 189 rated critical and 694 rated high severity. The average CVSS score for CWE-121 vulnerabilities is 8.1.

External reference: View CWE-121 on MITRE CWE →

Monitor CWE-121 Vulnerabilities

Get alerted when new CWE-121 CVEs affect your infrastructure.

Start Monitoring Free