Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-120

MITRE ↗

CWE-120

900
CRITICAL
2,344
HIGH
947
MEDIUM
52
LOW
4,280 CVEs · Page 8/86
7.8
CVE-2026-30979

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.8
CVE-2026-30983

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.8
CVE-2026-30985

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.8
CVE-2026-30987

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.8
CVE-2026-31795

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.8
CVE-2026-2920

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a

7.8
CVE-2026-3081

GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows

7.8
CVE-2026-3082

GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a

7.8
CVE-2025-47389

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

7.8
CVE-2026-21382

Memory Corruption when handling power management requests with improperly sized input/output buffers.

7.8
CVE-2026-4153

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a

7.8
CVE-2018-25302

Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulner

7.8
CVE-2026-6691

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling

7.8
CVE-2026-7452

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal

7.8
CVE-2026-7454

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal

7.8
CVE-2026-28580

In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to lo

7.8
CVE-2026-0138

In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This coul

7.8
CVE-2026-57246

When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature

7.8
CVE-2026-28981

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma

7.8
CVE-2026-43776

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO

7.8
CVE-2026-64747

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO

7.8
CVE-2026-24080

Memory Corruption when handling malformed request parameters in the fingerprint TA.

7.8
CVE-2026-19568

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal

7.8
CVE-2026-71399

Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of

7.7
CVE-2026-25506

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can

7.7
CVE-2026-20100

A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security A

7.6
CVE-2026-6688

FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling.

7.6
CVE-2026-80186

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bl

7.5
CVE-2025-69259

A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create

7.5
CVE-2025-69260

A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-

7.5
CVE-2021-47797

Leawo Prof. Media 11.0.0.1 contains a denial of service vulnerability that allows attackers to crash the application by

7.5
CVE-2021-47813

Backup Key Recovery 2.2.7 contains a denial of service vulnerability that allows attackers to crash the application by o

7.5
CVE-2021-47814

NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing

7.5
CVE-2021-47815

Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to

7.5
CVE-2020-36995

Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application

7.5
CVE-2020-37130

Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers

7.5
CVE-2020-37107

Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting

7.5
CVE-2020-37109

aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by ov

7.5
CVE-2020-37155

Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash th

7.5
CVE-2020-37175

P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability that allows attackers to crash the application by

7.5
CVE-2020-37179

APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the applicatio

7.5
CVE-2020-37180

GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by

7.5
CVE-2020-37185

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by o

7.5
CVE-2020-37187

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration name input field that allows attackers t

7.5
CVE-2020-37188

SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers

7.5
CVE-2020-37189

TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers t

7.5
CVE-2020-37190

Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the

7.5
CVE-2020-37191

Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to

7.5
CVE-2020-37193

ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by

7.5
CVE-2020-37194

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by s

Frequently Asked Questions

What is CWE-120?

CWE-120 (CWE-120) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-120?

There are 5,353 CVE records associated with CWE-120 in our database. Of these, 900 are critical severity, 2344 are high severity, and 947 are medium severity.

How can I protect against CWE-120 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-120 using AI-powered security agents.

Detect CWE-120 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-120 vulnerabilities across your infrastructure.

Get Started