Skip to main content

CWE archive

CWE-120 CVEs

Programmatic archive

4,352 CVEs tagged with CWE-120896 Critical, 2,274 High, 1,106 Medium, 76 Low, 0 Unrated.

CVE-2026-36799

Published Jun 9, 2026

Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAuth parameter of the formPortalAuth function. This vulnerability a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-36797

Published Jun 9, 2026

Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function. This vulner…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-36796

Published Jun 9, 2026

Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulner…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-30141

Published Jun 9, 2026

An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially exe…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-46332

Published Jun 9, 2026

In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive buffering cc1352_bootloader_rx() appends each serdev chunk i…

CVSS 8.0 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-9698

Published Jun 9, 2026

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
43.5
Vendor/product tagsBeta · best-effort

CVE-2026-42536

Published Jun 8, 2026

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2…

CVSS 7.5 · High
evidence mentions
12
Buzz score
45.1
Vendor/product tagsBeta · best-effort

CVE-2026-34355

Published Jun 8, 2026

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fi…

CVSS 7.5 · High
evidence mentions
12
Buzz score
45.1
Vendor/product tagsBeta · best-effort

CVE-2026-11517

Published Jun 8, 2026

A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /goform/formConfigDnsFilterGlobal. Executing a manipulation of t…

CVSS 7.4 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-11516

Published Jun 8, 2026

A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument N…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
26.0

CVE-2019-25741

Published Jun 4, 2026

Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to ex…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2019-25736

Published Jun 4, 2026

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. A…

CVSS 8.6 · High
evidence mentions
3
Buzz score
25.4

CVE-2019-25735

Published Jun 4, 2026

AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively…

CVSS 8.6 · High
evidence mentions
4
Buzz score
29.1

CVE-2019-25733

Published Jun 4, 2026

NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. A…

CVSS 8.6 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-30652

Published Jun 2, 2026

A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a.…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30650

Published Jun 2, 2026

A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware ve…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3871

Published Jun 2, 2026

A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigge…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-3870

Published Jun 2, 2026

A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-28580

Published Jun 1, 2026

In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution pr…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0056

Published Jun 1, 2026

In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional executio…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-25432

Published Jun 1, 2026

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft…

CVSS 8.6 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-10275

Published Jun 1, 2026

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module…

CVSS 1.3 · Low
evidence mentions
10
Buzz score
37.0

CVE-2026-10164

Published May 31, 2026

A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. The manipulatio…

CVSS 7.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-10163

Published May 31, 2026

A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. T…

CVSS 7.4 · High
evidence mentions
4
Buzz score
22.6
Showing 126-150 of 4,352 CVEsPage 6 of 175