A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Volume of CVEs assigned to CWE-121 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
3,521 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-22457CRITICAL A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows | Apr 3, 2025 | 9.8 | 99 | YES | YES |
CVE-2025-0282CRITICAL A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22. | Jan 8, 2025 | 9.0 | 98 | YES | YES |
CVE-2021-20038CRITICAL A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute cod | Dec 8, 2021 | 9.8 | 98 | YES | YES |
CVE-2009-0927HIGH Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argu | Mar 19, 2009 | 8.8 | 98 | YES | YES |
CVE-2008-0015HIGH Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in Dir | Jul 7, 2009 | 8.8 | 97 | YES | YES |
CVE-2022-20699CRITICAL Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr | Feb 10, 2022 | 9.8 | 95 | YES | YES |
CVE-2020-5735HIGH Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly exec | Apr 8, 2020 | 8.8 | 88 | YES | YES |
CVE-2016-6563CRITICAL Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP | Jul 13, 2018 | 9.8 | 87 | NO | YES |
CVE-2025-20352HIGH A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:
An authenticated, remote | Sep 24, 2025 | 7.7 | 85 | YES | NO |
CVE-2025-32756CRITICAL A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMa | May 13, 2025 | 9.8 | 85 | YES | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.