Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-121

MITRE ↗

CWE-121

678
CRITICAL
2,274
HIGH
569
MEDIUM
39
LOW
3,665 CVEs · Page 16/74
7.5
CVE-2026-51605

A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unaut

7.5
CVE-2026-55687

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possib

7.5
CVE-2026-40553

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue

7.5
CVE-2026-51105

Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via t

7.5
CVE-2026-50695

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over

7.5
CVE-2026-54983

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv

7.5
CVE-2026-50304

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over

7.5
CVE-2026-50355

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over

7.5
CVE-2026-50368

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over

7.5
CVE-2026-50411

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv

7.5
CVE-2026-47477

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overf

7.5
CVE-2026-50527

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

7.5
CVE-2026-48863

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to

7.5
CVE-2026-50039

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corru

7.5
CVE-2026-58180

The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache

7.5
CVE-2026-58181

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue

7.5
CVE-2026-11771

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the

7.5
CVE-2026-43829

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-43831

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-43832

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-15722

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function

7.5
CVE-2026-71265

Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data

7.5
CVE-2026-67866

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Lock

7.5
CVE-2026-20345

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

7.5
CVE-2026-71979

INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack bu

7.5
CVE-2026-73522

COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attacker

7.5
CVE-2026-45798

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 an

7.5
CVE-2026-76879

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

7.5
CVE-2026-75368

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause

7.5
CVE-2026-68863

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthentica

7.5
CVE-2026-67560

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A

7.4
CVE-2026-25967

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15

7.4
CVE-2026-25968

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

7.4
CVE-2026-25570

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform che

7.4
CVE-2026-49014

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buf

7.4
CVE-2026-4017

Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause

7.3
CVE-2025-15555

A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_

7.3
CVE-2025-69720

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in prog

7.3
CVE-2026-33147

GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions

7.3
CVE-2026-38422

Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary cod

7.3
CVE-2026-30649

Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via th

7.3
CVE-2026-12200

A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown functi

7.3
CVE-2026-49789

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.3
CVE-2026-18871

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerab

7.3
CVE-2026-82478

A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_req

7.2
CVE-2025-37169

A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exp

7.2
CVE-2026-2191

A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This man

7.2
CVE-2026-2192

A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the functio

7.2
CVE-2026-2566

A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260. This affects the function sub_406194 of

7.2
CVE-2026-2567

A vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the f

Frequently Asked Questions

What is CWE-121?

CWE-121 (CWE-121) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-121?

There are 3,705 CVE records associated with CWE-121 in our database. Of these, 678 are critical severity, 2274 are high severity, and 569 are medium severity.

How can I protect against CWE-121 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-121 using AI-powered security agents.

Detect CWE-121 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-121 vulnerabilities across your infrastructure.

Get Started