VulnSea

CWE-121

CVEs classified under CWE-121, newest first.

286 CVEsRSS

CVE-2026-61674Critical· 9.2
today

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the …

Midnightfluent · fluent-bitvia NVD
CVE-2026-94184High· 8.1
today

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixe…

TwilightRed Hat · fetchmailvia NVD
CVE-2026-94089Critical· 10.0
yesterday

A vulnerability was determined in D-Link DIR-868L 2.01b05

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lea…

MidnightD-Link · DIR-868LEPSS 0.98%via NVD
CVE-2026-94003Critical· 10.0
yesterday

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. …

MidnightComfast · CF-N1-SEPSS 0.61%via NVD
CVE-2026-61548High· 8.1
3d ago

Rsyslog is a rocket-fast system for log processing

Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] st…

Twilightrsyslog · rsyslogEPSS 0.59%via NVD
CVE-2026-59181Medium· 6.1PoC
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value g…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-81945Medium· 6.6
3d ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer a…

SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.43%via NVD
CVE-2026-81946Medium· 4.4
3d ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device confi…

SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.12%via NVD
CVE-2026-81944High· 7.5
3d ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer …

TwilightPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.53%via NVD
CVE-2026-93372Critical· 9.6
4d ago

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Midnightgoogle · chromeEPSS 0.40%via NVD
CVE-2026-19477High· 7.8
4d ago

There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution

There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Universal Library f…

TwilightMCC · Universal Library for Linux (uldaq)EPSS 0.13%via NVD
CVE-2026-90823Critical· 9.8
4d ago

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management…

MidnightFatPipe Networks · MPVPNEPSS 0.68%via NVD
CVE-2026-81480High· 7.2
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.62%via NVD
CVE-2026-25283High· 8.8
4d ago

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

TwilightQualcomm, Inc. · SnapdragonEPSS 0.11%via NVD
CVE-2026-81546High· 7.7
4d ago

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity documen…

TwilightCanva · AffinityEPSS 0.11%via NVD
CVE-2026-86358Medium· 6.5
5d ago

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote exe…

SunlitDell · Update Package FrameworkEPSS 0.30%via NVD
CVE-2026-91843Critical· 9.8PoC
5d ago

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Abyssalcheckpoint · Quantum Security ManagementEPSS 0.50%via NVD
CVE-2026-76869High· 7.2
6d ago

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted input to the affected endpoint to corrupt st…

TwilightNetcore · NR255-VEPSS 0.43%via NVD
CVE-2026-76861High· 8.8
6d ago

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflo…

TwilightNetcore · NR255-VEPSS 0.51%via NVD
CVE-2026-76860High· 8.8
6d ago

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the st…

TwilightNetcore · NR255-VEPSS 0.41%via NVD
CVE-2026-19774High· 7.10day
6d ago

BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability

BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to p…

AbyssalBlueZ · BlueZEPSS 0.33%via NVD
CVE-2026-12150High· 7.0
6d ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trus…

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trus…

TwilightIBM · MQEPSS 0.17%via NVD
CVE-2026-91826Medium· 4.4
6d ago

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

SunlitSamsung Opensource · rLottieEPSS 0.11%via NVD
CVE-2026-91090Low· 3.9
6d ago

A vulnerability was determined in GPAC up to f1219cde

A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the …

SunlitEPSS 0.12%via NVD
CVE-2026-91003Critical· 9.1PoC
6d ago

A flaw has been found in D-Link DI-8300 16.07

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exp…

AbyssalD-Link · DI-8300EPSS 0.51%via NVD
CVE-2026-91001Critical· 9.9PoC
6d ago

A security flaw has been discovered in D-Link DI-8400 16.07

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip resul…

AbyssalD-Link · DI-8400EPSS 0.48%via NVD
CVE-2026-90824Low· 3.3PoC
1w ago

A vulnerability has been found in GPAC 26.07.0

A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to stack-based buffer overflow. The attack can only b…

TwilightEPSS 0.17%via NVD
CVE-2026-89020Medium· 4.3
1w ago

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by sup…

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by sup…

SunlitMikroTik · RouterOSEPSS 0.29%via NVD
CVE-2026-19542Medium· 5.6
1w ago

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an expl…

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an expl…

SunlitThe GNU C Library · glibcEPSS 0.28%via NVD
CVE-2026-33963High· 7.5
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of serv…

TwilightSamsung · Exynos 1330 firmwareEPSS 0.11%via NVD
CWE-121 vulnerabilities (CVEs) · VulnSea