CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
379 vulnerabilities with CWE-134
CVE-2026-6539
MEDIUM
Notepad++ 8.9.3 Format String Injection via nativeLang.xml
CVSS 4.4
CVE-2026-3008
MEDIUM
Vulnerability in Notepad++
CVSS 6.6
CVE-2026-6843
MEDIUM
Nano: nano: format string vulnerability leads to denial of service
CVSS 5.5
CVE-2026-3509
HIGH
CODESYS Control Audit Log Format String DoS
CVSS 7.5
CVE-2026-33210
CRITICAL
Ruby JSON has a format string injection vulnerability
CVSS 9.1
CVE-2026-0400
MEDIUM
SonicOS - Format String DoS
CVSS 4.9
CVE-2026-21640
LOW
Aquaplatform Revive Adserver < 6.0.4 - Format String Vulnerability
CVSS 2.7
CVE-2026-22190
HIGH
CMU Panda3d < 1.10.16 - Format String Vulnerability
CVSS 7.5
CVE-2025-68648
HIGH
Fortinet FortiAnalyzer/FortiManager - Memory Corruption
CVSS 7.2
CVE-2025-30269
HIGH
Qsync Central <5.0.0.4 - Memory Corruption
CVSS 8.1
CVE-2025-64157
MEDIUM
Fortinet Fortios < 7.4.10 - Format String Vulnerability
CVSS 6.7
CVE-2025-68949
MEDIUM
n8n <2.2.0 - Info Disclosure
CVSS 5.3
CVE-2025-53591
MEDIUM
QNAP OS - Info Disclosure
CVSS 6.5
CVE-2025-52666
LOW
Revive-adserver Revive Adserver < 5.5.2 - Format String Vulnerability
CVSS 2.7
CVE-2025-48826
HIGH
Planet WGR-500 <1.3411b190912 - Memory Corruption
CVSS 8.8
CVE-2025-53407
MEDIUM
QNAP OS - Info Disclosure
CVSS 6.5
CVE-2025-53406
MEDIUM
QNAP OS - Info Disclosure
CVSS 6.5
CVE-2025-52429
MEDIUM
Qnap Qts - Format String Vulnerability
CVSS 6.5
CVE-2025-48730
MEDIUM
QNAP OS - Info Disclosure
CVSS 6.5
CVE-2025-36202
HIGH
IBM Webmethods Integration - Format String Vulnerability
CVSS 7.5
CVE-2025-55298
HIGH
ImageMagick <6.9.13-28 & <7.1.2 - RCE
CVSS 7.5
CVE-2025-40600
CRITICAL
Sonicwall Sonicos < 7.3.0-7012 - Format String Vulnerability
CVSS 9.8
CVE-2025-46123
HIGH
Ruckuswireless Ruckus Unleashed - Format String Vulnerability
CVSS 7.2
CVE-2025-46121
CRITICAL
Ruckuswireless Ruckus Unleashed - Format String Vulnerability
CVSS 9.8
CVE-2025-22482
HIGH
Qnap Qsync Central < 4.5.0.6 - Format String Vulnerability
CVSS 8.1
Details
Vulnerabilities
379
Exploit Likelihood
High