VulnSea

CWE-121

CVEs classified under CWE-121, newest first.

345 CVEsRSS

CVE-2026-76879High· 7.5
1mo ago

Stack-based Buffer Overflow in Wireshark

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.31%via CVEORG
CVE-2026-75142High· 7.8
1mo ago

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c)

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted in…

▾ TwilightEPSS 0.20%via NVD
CVE-2026-45798High· 7.5
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field…

▾ Twilightwazuh · wazuhEPSS 0.92%via NVD
CVE-2026-16872Critical· 9.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

▾ Midnightibm · viosEPSS 0.80%via NVD
CVE-2026-17494High· 8.2
1mo ago

IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system

IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, a…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-16832High· 8.4
1mo ago

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC admin…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-16687Critical· 9.6
1mo ago

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can …

▾ MidnightEPSS 0.35%via NVD
CVE-2026-76003Critical· 9.9
1mo ago

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The a…

▾ MidnightEPSS 0.79%via NVD
CVE-2026-73522High· 7.5
1mo ago

COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-…

COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-…

▾ TwilightEPSS 4.0%via NVD
CVE-2026-71979High· 7.5
1mo ago

INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash the daemon by sending malformed XML…

INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash the daemon by sending malformed XML…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-54758High· 7.8
1mo ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a Notepad++ variable name between $( and ) into the fixed-…

▾ TwilightEPSS 0.19%via NVD
CVE-2026-67967Critical· 9.8
1mo ago

Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code

Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819

▾ MidnightEPSS 0.65%via NVD
CVE-2026-19933Medium· 6.3
1mo ago

A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0

A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function gets of the component Customer Search Module. This manipulation causes stack-based buffer overflow. The attack m…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-14679High· 8.2
1mo ago

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, …

▾ Twilightpostgresql · postgresqlEPSS 0.29%via NVD
CVE-2026-19003High· 7.8
1mo ago

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calcul…

▾ Twilightmongodb · bi_connector_odbc_driverEPSS 0.21%via NVD
CVE-2026-71407Medium· 5.6
1mo ago

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the conte…

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the conte…

▾ Sunlitfortinet · fortiosEPSS 0.42%via NVD
CVE-2026-73070Medium· 5.5
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/c…

▾ Sunlitvim · vimEPSS 0.19%via NVD
CVE-2026-70346High· 7.8
1mo ago

Windows Installer Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-70344High· 7.8
1mo ago

Windows Installer Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62755High· 7.8
1mo ago

Windows DHCP Client Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62878Critical· 9.8PoC
1mo ago

Windows DNS Server Remote Code Execution Vulnerability

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

▾ AbyssalMicrosoft · Windows Server 2012EPSS 0.97%via CVEORG
CVE-2026-62877High· 7.8
1mo ago

Windows Win32k Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62792High· 8.1
1mo ago

Windows TCP/IP Remote Code Execution Vulnerability

Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.71%via CVEORG
CVE-2026-68795High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-68816High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-62824High· 8.8
1mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.82%via CVEORG
CVE-2026-62768High· 7.8
1mo ago

Windows Installer Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-63527High· 7.8
1mo ago

Microsoft Office Word Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-63526High· 7.8
1mo ago

Microsoft Office Graphics Component Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-64919High· 7.8
1mo ago

Microsoft Access Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CWE-121 vulnerabilities (CVEs) — page 6 · VulnSea