Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-122

MITRE ↗

CWE-122

257
CRITICAL
1,911
HIGH
479
MEDIUM
65
LOW
2,756 CVEs · Page 20/56
9.8
CVE-2025-47981

Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a

9.8
CVE-2025-54949

A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or oth

9.8
CVE-2025-54951

A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash an

9.8
CVE-2025-53766

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

9.8
CVE-2025-48005

A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3

9.8
CVE-2025-53511

A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.

9.8
CVE-2025-53557

A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.

9.8
CVE-2025-53853

A heap-based buffer overflow vulnerability exists in the ISHNE parsing functionality of The Biosig Project libbiosig 3.9

9.8
CVE-2025-54462

A heap-based buffer overflow vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0

9.8
CVE-2025-34522

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP).

9.8
CVE-2025-34523

A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data

9.8
CVE-2025-26416

In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow.

9.8
CVE-2025-58447

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior

9.8
CVE-2025-60724

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a networ

9.8
CVE-2025-64693

Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Con

9.8
CVE-2025-65085

A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v

9.8
CVE-2025-11778

Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely

9.8
CVE-2025-11788

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' f

9.8
CVE-2025-50343

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfie

9.4
CVE-2025-30216

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL

9.4
CVE-2025-24797

Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protob

9.3
CVE-2025-54574

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possi

9.1
CVE-2025-23317

NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shel

9.1
CVE-2025-58050

The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-b

9.1
CVE-2025-62608

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflo

9.0
CVE-2025-20363

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Fi

8.9
CVE-2025-55118

Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issu

8.8
CVE-2025-21178

Visual Studio Remote Code Execution Vulnerability

8.8
CVE-2025-21223

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21233

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21236

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21237

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21238

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21239

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21240

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21241

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21245

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21246

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21248

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21250

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21252

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21266

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21273

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21282

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21286

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21302

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21303

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21305

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21306

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21339

Windows Telephony Service Remote Code Execution Vulnerability

Frequently Asked Questions

What is CWE-122?

CWE-122 (CWE-122) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-122?

There are 2,806 CVE records associated with CWE-122 in our database. Of these, 257 are critical severity, 1911 are high severity, and 479 are medium severity.

How can I protect against CWE-122 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-122 using AI-powered security agents.

Detect CWE-122 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-122 vulnerabilities across your infrastructure.

Get Started