Skip to main content

CWE archive

CWE-121 CVEs

Programmatic archive

3,527 CVEs tagged with CWE-121584 Critical, 2,300 High, 572 Medium, 71 Low, 0 Unrated.

CVE-2026-43771

Published Jul 27, 2026

A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a de…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-51244

Published Jul 27, 2026

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in UnpackFrameHeader(). Multiple attacker-controlled index parameters are used to access static and heap tabl…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-12495

Published Jul 27, 2026

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-55728

Published Jul 24, 2026

Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX…

CVSS 3.8 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-16870

Published Jul 24, 2026

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overf…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50039

Published Jul 23, 2026

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64831

Published Jul 22, 2026

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-61391

Published Jul 22, 2026

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted pa…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16418

Published Jul 21, 2026

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium securi…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-59144

Published Jul 21, 2026

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-16461

Published Jul 21, 2026

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are writte…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-15370

Published Jul 21, 2026

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes…

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2024-51315

Published Jul 20, 2026

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2024-51314

Published Jul 20, 2026

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2024-51312

Published Jul 20, 2026

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2024-51313

Published Jul 20, 2026

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2024-51311

Published Jul 20, 2026

The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-48389

Published Jul 20, 2026

DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current use…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16277

Published Jul 20, 2026

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copie…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
37.9

CVE-2026-16248

Published Jul 20, 2026

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. Th…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-16097

Published Jul 18, 2026

A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 re…

CVSS 8.7 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-16096

Published Jul 18, 2026

A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads…

CVSS 8.7 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-52584

Published Jul 17, 2026

Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2021-27137

Published Jul 16, 2026

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a r…

CVSS 8.1 · High
evidence mentions
9
Buzz score
68.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-56455

Published Jul 16, 2026

HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an att…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 3,527 CVEsPage 1 of 142