VulnSea

CWE-120

CVEs classified under CWE-120, newest first.

283 CVEsRSS

CVE-2020-37211High· 7.5
7mo ago

SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field

SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name'…

▾ Twilightnsasoft · spotimEPSS 0.29%via NVD
CVE-2020-37210High· 7.5
7mo ago

SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application

SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an …

▾ Twilightnsasoft · spotieEPSS 0.29%via NVD
CVE-2020-37209High· 7.5
7mo ago

SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application

SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to …

▾ Twilightnsasoft · spotftpEPSS 0.32%via NVD
CVE-2020-37207High· 7.5
7mo ago

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to t…

▾ Twilightnsasoft · spotdialupEPSS 0.38%via NVD
CVE-2020-37206High· 7.5
7mo ago

ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key

ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload to trigger an application crash wh…

▾ Twilightnsasoft · sharealarmproEPSS 0.38%via NVD
CVE-2020-37205High· 7.5
7mo ago

RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' registration field

RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' registration field. Attackers can generate a 1000-character buffer payload and paste it into the regi…

▾ Twilightnsasoft · remshutdownEPSS 0.40%via NVD
CVE-2020-37204High· 7.5
7mo ago

RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application

RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration key fi…

▾ Twilightnsasoft · remshutdownEPSS 0.40%via NVD
CVE-2020-37201High· 7.5
7mo ago

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to crash the application

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger…

▾ Twilightnsasoft · netsharewatcherEPSS 0.36%via NVD
CVE-2020-37199High· 7.5
7mo ago

NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application

NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigge…

▾ Twilightnsasoft · nbmonitorEPSS 0.46%via NVD
CVE-2020-37197High· 7.5
7mo ago

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character buffer payload and paste it into th…

▾ Twilightnsasoft · domain_name_search_softwareEPSS 0.46%via NVD
CVE-2020-37196High· 7.5
7mo ago

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by providing an oversized registration key

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by providing an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it in…

▾ Twilightnsasoft · domain_name_search_softwareEPSS 0.46%via NVD
CVE-2026-25506High· 7.7
7mo ago

MUNGE is an authentication service for creating and validating user credentials

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key materia…

▾ Twilightopensuse · mungeEPSS 0.27%via NVD
CVE-2020-37131Medium· 6.2
7mo ago

Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key

Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of r…

▾ Sunlitnsasoft · product_key_explorerEPSS 0.24%via NVD
CVE-2025-15467High· 8.8PoC
8mo ago

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …

▾ Midnightopenssl · opensslEPSS 52%via NVD
CVE-2025-55131High· 7.1
8mo ago

A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option

A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and…

▾ TwilightEPSS 3.5%via NVD
CVE-2021-47814High· 7.5
8mo ago

NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field

NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to tri…

▾ Twilightnsasoft · nbmonitorEPSS 0.42%via NVD
CVE-2025-29329Critical· 9.8
8mo ago

Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.

Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.

▾ Midnightsagemcom · f@st_3686_firmwareEPSS 0.98%via NVD
CVE-2026-22184High· 7.8
8mo ago

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compressi…

▾ Twilightzlib · zlibEPSS 0.42%via NVD
CVE-2025-8065Medium· 6.5
9mo ago

A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6

A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it t…

▾ Sunlittp-link · tapo_c200_firmwareEPSS 0.53%via NVD
CVE-2025-14187High· 7.2
9mo ago

A weakness has been identified in UGREEN DH2100+ up to 5.3.0.251125

A weakness has been identified in UGREEN DH2100+ up to 5.3.0.251125. This affects the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. Executing a manipulation of the argument path can lead…

▾ TwilightEPSS 0.63%via NVD
CVE-2025-64053High· 7.5
9mo ago

A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.

A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.

▾ Twilightfanvil · x210_firmwareEPSS 2.9%via NVD
CVE-2025-66287High· 8.8
9mo ago

A flaw was found in WebKitGTK

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

▾ TwilightEPSS 0.47%via NVD
CVE-2025-43441Medium· 4.3
10mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may…

▾ Sunlitapple · safariEPSS 0.90%via NVD
CVE-2025-43433High· 8.8
10mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted w…

▾ Twilightapple · safariEPSS 1.1%via NVD
CVE-2025-20149Medium· 6.5
1y ago

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnera…

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnera…

▾ Sunlitcisco · iosEPSS 0.12%via NVD
CVE-2025-9962None
1y ago

A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authentication.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97…

A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authentication.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97…

▾ SunlitEPSS 1.1%via NVD
CVE-2025-9961NonePoC
1y ago

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.…

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.…

▾ TwilightEPSS 10.0%via NVD
CVE-2025-9813High· 8.8
1y ago

A vulnerability was identified in Tenda CH22 1.0.0.1

A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /goform/SetSambaConf. The manipulation of the argument samba_userNameSda leads to buffer overflow. It is possible to initi…

▾ Twilighttenda · ch22_firmwareEPSS 0.87%via NVD
CVE-2025-9812High· 8.8
1y ago

A vulnerability was determined in Tenda CH22 1.0.0.1

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Executing manipulation of the argument cmdinput can lead to buffer overflow. The attack may be p…

▾ Twilighttenda · ch22_firmwareEPSS 0.66%via NVD
CVE-2025-9783High· 8.8
1y ago

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentControl. Executing manipulation of the argument submit-url can lead to buffer overflow. The a…

▾ Twilighttotolink · a702r_firmwareEPSS 0.66%via NVD
CWE-120 vulnerabilities (CVEs) — page 8 · VulnSea