Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-121

MITRE ↗

CWE-121

678
CRITICAL
2,274
HIGH
569
MEDIUM
39
LOW
3,665 CVEs · Page 13/74
7.8
CVE-2026-57091

Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-47971

Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i

7.8
CVE-2026-48389

DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in

7.8
CVE-2026-5056

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote atta

7.8
CVE-2026-10709

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab

7.8
CVE-2026-10710

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab

7.8
CVE-2026-71266

tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a f

7.8
CVE-2026-21068

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execut

7.8
CVE-2026-59086

A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606).

7.8
CVE-2026-62755

Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62768

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62877

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-63526

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-63527

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-64907

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-64912

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-64919

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-66807

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68795

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68816

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68817

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-70344

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-70346

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-19003

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setu

7.8
CVE-2026-54758

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEd

7.8
CVE-2026-75142

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing

7.8
CVE-2026-18297

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows re

7.8
CVE-2026-18303

GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote

7.8
CVE-2026-16945

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-base

7.8
CVE-2026-48417

Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-77658

A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Di

7.7
CVE-2026-30929

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

7.6
CVE-2025-69195

A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization lo

7.6
CVE-2026-6687

FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trus

7.5
CVE-2025-65805

OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote at

7.5
CVE-2025-70753

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_4CA50 function

7.5
CVE-2025-71023

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the mac2 parameter of the fromAdvSetMacMtuWan f

7.5
CVE-2025-71024

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMac

7.5
CVE-2025-71025

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMt

7.5
CVE-2025-71026

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtu

7.5
CVE-2025-71027

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWa

7.5
CVE-2025-70747

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function

7.5
CVE-2025-71021

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function.

7.5
CVE-2025-70744

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function.

7.5
CVE-2025-71019

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. T

7.5
CVE-2025-70304

A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Serv

7.5
CVE-2025-70656

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This v

7.5
CVE-2025-70307

A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via

7.5
CVE-2021-47789

Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash t

7.5
CVE-2025-70746

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime functi

Frequently Asked Questions

What is CWE-121?

CWE-121 (CWE-121) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-121?

There are 3,705 CVE records associated with CWE-121 in our database. Of these, 678 are critical severity, 2274 are high severity, and 569 are medium severity.

How can I protect against CWE-121 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-121 using AI-powered security agents.

Detect CWE-121 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-121 vulnerabilities across your infrastructure.

Get Started