Skip to main content

CWE archive

CWE-120 CVEs

Programmatic archive

4,317 CVEs tagged with CWE-120885 Critical, 2,249 High, 1,108 Medium, 75 Low, 0 Unrated.

CVE-2026-43776

Published Jul 27, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously cr…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-59250

Published Jul 27, 2026

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code…

CVSS 8.3 · High
evidence mentions
5
Buzz score
30.9

CVE-2026-45811

Published Jul 24, 2026

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-63453

Published Jul 21, 2026

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execut…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44880

Published Jul 21, 2026

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to ex…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44436

Published Jul 16, 2026

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack t…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-32389

Published Jul 16, 2026

Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs comp…

CVSS 3.5 · Low
evidence mentions
2
Buzz score
17.5

CVE-2026-51380

Published Jul 15, 2026

Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cg…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-58553

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58552

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58551

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58550

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58549

Published Jul 15, 2026

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-51808

Published Jul 14, 2026

Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2025-11698

Published Jul 14, 2026

A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-12012

Published Jul 14, 2026

A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing t…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-12011

Published Jul 14, 2026

A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a majo…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-8412

Published Jul 14, 2026

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the regist…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-15543

Published Jul 13, 2026

A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buff…

CVSS 7.4 · High
evidence mentions
6
Buzz score
34.5

CVE-2026-15484

Published Jul 12, 2026

A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulat…

CVSS 8.7 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-15483

Published Jul 12, 2026

A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipul…

CVSS 8.7 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-29009

Published Jul 8, 2026

U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised N…

CVSS 8.8 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-8247

Published Jul 3, 2026

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerab…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 4,317 CVEsPage 1 of 173