Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-787

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

14,355
Assigned CVEs
4th
Commonality Rank
8.0
Avg CVSS
1.1%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-787 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Jul 24, 2026
0 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

14,355 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-22457CRITICAL
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows
Apr 3, 20259.899YESYES
CVE-2025-9242CRITICAL
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile Use
Sep 17, 20259.898YESYES
CVE-2025-0282CRITICAL
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.
Jan 8, 20259.098YESYES
CVE-2023-34048CRITICAL
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou
Oct 25, 20239.898YESYES
CVE-2023-4911HIGH
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us
Oct 3, 20237.898YESYES
CVE-2022-42475CRITICAL
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an
Jan 2, 20239.898YESYES
CVE-2021-4034HIGH
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri
Jan 28, 20227.898YESYES
CVE-2021-20038CRITICAL
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute cod
Dec 8, 20219.898YESYES
CVE-2019-11043CRITICAL
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff
Oct 28, 20199.898YESYES
CVE-2018-0171CRITICAL
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected devi
Mar 28, 20189.898YESYES
View all 14,355 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
10%
16%
6.0-6.9
44%
26%
7.0-7.9
18%
11%
8.0-8.9
19%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
159 CVEs
1.1% of CVEs· 92nd percentile
Metasploit
61 CVEs
0.4% of CVEs· 82nd percentile
Nuclei
14 CVEs
0.1% of CVEs· 77th percentile
ExploitDB
229 CVEs
1.6% of CVEs· 86th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products