Skip to main content

CWE archive

CWE-120 CVEs

Programmatic archive

4,314 CVEs tagged with CWE-120885 Critical, 2,246 High, 1,108 Medium, 75 Low, 0 Unrated.

CVE-2019-25735

Published Jun 4, 2026

AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively…

CVSS 8.6 · High
evidence mentions
4
Buzz score
29.1

CVE-2019-25733

Published Jun 4, 2026

NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. A…

CVSS 8.6 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-30652

Published Jun 2, 2026

A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a.…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30650

Published Jun 2, 2026

A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware ve…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3871

Published Jun 2, 2026

A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigge…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-3870

Published Jun 2, 2026

A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-28580

Published Jun 1, 2026

In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution pr…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0056

Published Jun 1, 2026

In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional executio…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-25432

Published Jun 1, 2026

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft…

CVSS 8.6 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-10275

Published Jun 1, 2026

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module…

CVSS 1.3 · Low
evidence mentions
10
Buzz score
37.0

CVE-2026-10164

Published May 31, 2026

A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. The manipulatio…

CVSS 7.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-10163

Published May 31, 2026

A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. T…

CVSS 7.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-10126

Published May 30, 2026

A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The…

CVSS 7.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2018-25426

Published May 30, 2026

WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated cha…

CVSS 8.7 · High
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2018-25423

Published May 30, 2026

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a maliciou…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-38426

Published May 27, 2026

Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scripter.ino, fetch_jpg(), jpg_task.bound…

CVSS 7.3 · High
evidence mentions
2
Buzz score
20.0
Public PoC observed

CVE-2025-12686

Published May 27, 2026

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-9627

Published May 27, 2026

A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interfac…

CVSS 7.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-7454

Published May 26, 2026

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arb…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-7452

Published May 26, 2026

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arb…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-48696

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-48686

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2018-25377

Published May 25, 2026

Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting str…

CVSS 8.6 · High

CVE-2018-25376

Published May 25, 2026

Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structure…

CVSS 8.6 · High
Showing 101-125 of 4,314 CVEsPage 5 of 173