Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-121

MITRE ↗

CWE-121

678
CRITICAL
2,274
HIGH
569
MEDIUM
39
LOW
3,665 CVEs · Page 12/74
7.8
CVE-2026-25502

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color

7.8
CVE-2026-25584

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color

7.8
CVE-2026-22923

A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected

7.8
CVE-2025-70083

An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and

7.8
CVE-2019-25435

Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function tha

7.8
CVE-2026-27821

GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs dur

7.8
CVE-2025-70616

A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the I

7.8
CVE-2026-26738

Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary c

7.8
CVE-2026-30983

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.8
CVE-2026-30987

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.8
CVE-2026-31795

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.8
CVE-2026-27267

Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could res

7.8
CVE-2026-32708

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack

7.8
CVE-2026-3081

GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows

7.8
CVE-2026-33491

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based

7.8
CVE-2026-32925

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Open

7.8
CVE-2026-32928

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Op

7.8
CVE-2025-47391

Memory corruption while processing a frame request from user.

7.8
CVE-2026-5726

ASDA-Soft Stack-based Buffer Overflow Vulnerability

7.8
CVE-2026-39853

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vul

7.8
CVE-2026-39457

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whethe

7.8
CVE-2026-34461

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI

7.8
CVE-2026-34462

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P

7.8
CVE-2026-44412

A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected applications con

7.8
CVE-2026-40399

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an

7.8
CVE-2026-34690

After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i

7.8
CVE-2026-45250

The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is

7.8
CVE-2026-43958

A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a

7.8
CVE-2026-50256

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the

7.8
CVE-2026-50258

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers

7.8
CVE-2026-50259

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-siz

7.8
CVE-2026-34695

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that coul

7.8
CVE-2026-34697

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that coul

7.8
CVE-2026-34702

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that coul

7.8
CVE-2026-34708

InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result i

7.8
CVE-2026-47959

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerabili

7.8
CVE-2026-11979

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. T

7.8
CVE-2026-14605

A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l

7.8
CVE-2026-14606

A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the

7.8
CVE-2026-49033

The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arb

7.8
CVE-2026-50318

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges

7.8
CVE-2026-55899

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50387

Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50400

Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50412

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50501

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loca

7.8
CVE-2026-55038

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55055

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55134

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55141

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Frequently Asked Questions

What is CWE-121?

CWE-121 (CWE-121) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-121?

There are 3,705 CVE records associated with CWE-121 in our database. Of these, 678 are critical severity, 2274 are high severity, and 569 are medium severity.

How can I protect against CWE-121 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-121 using AI-powered security agents.

Detect CWE-121 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-121 vulnerabilities across your infrastructure.

Get Started