CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
399 vulnerabilities with CWE-134
CVE-2026-67244
HIGH
A format string vulnerability was found in the Notification OAuth settings of ADM
CVE-2026-18188
HIGH
A format string vulnerability was found in the Rsync Backup on the ADM
CVE-2026-18187
HIGH
A format string vulnerability was found in the Internal Backup on the ADM
CVE-2026-18186
HIGH
A stored format string vulnerability was found in the FTP Backup on the ADM
CVE-2026-6390
MEDIUM
GNU nano Error Handling - Format String Memory Corruption
CVSS 6.8
CVE-2026-15809
HIGH
CRI-O - HOME Environment Variable /etc/passwd Injection
CVSS 7.8
CVE-2026-15680
HIGH
Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-46465
MEDIUM
Dell PowerProtect Data Domain - Use of Externally-Controlled Format String
CVSS 5.5
CVE-2026-57877
HIGH
GeoVision GV-LPCLPC2011/2211 - GV-LPC2011/LPC2211 - Unauthorized Format String Vulnerability (vlsvr)
CVSS 8.6
CVE-2026-10828
MEDIUM
Moxa NPort W2150A-W4/W2250A-W4 Series - Use of Externally-Controlled Format String
CVE-2026-12174
HIGH
D-Link DCS-935L HTTP rhea snprintf format string
CVSS 8.8
CVE-2026-6250
HIGH
Authenticated Format String Injection on TP-Link Tapo C110
CVSS 8.1
CVE-2026-6242
MEDIUM
Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Link Tapo C520WS
CVE-2026-6241
MEDIUM
Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Link Tapo C520WS
CVE-2026-50211
CRITICAL
Acer Connect M6E 5G Portable WiFi Router - Exposed Factory Testing App Boundaries
CVSS 9.8
CVE-2026-7835
LOW
Netatalk 3.0.3-4.4.2 - Authenticated Denial of Service via Format String Argument Mismatch
CVSS 3.1
CVE-2026-6474
MEDIUM
PostgreSQL timeofday() can disclose portions of server memory
CVSS 4.3
CVE-2026-44407
MEDIUM
Remote Denial of Service Vulnerability Exists in ZTE Cloud PC Client uSmartview
CVSS 4.7
CVE-2026-6539
MEDIUM
Notepad++ 8.9.3 Format String Injection via nativeLang.xml
CVSS 4.4
CVE-2026-3008
MEDIUM
Vulnerability in Notepad++
CVSS 6.6
CVE-2026-6843
MEDIUM
Nano: nano: format string vulnerability leads to denial of service
CVSS 5.5
CVE-2026-3509
HIGH
CODESYS Control Audit Log Format String DoS
CVSS 7.5
CVE-2026-33210
CRITICAL
Ruby JSON allow_duplicate_key - Format String Injection
CVSS 9.1
CVE-2026-0400
MEDIUM
SonicOS < 7.3.2-7010 - Authenticated Denial of Service via Format String Vulnerability
CVSS 4.9
CVE-2026-21640
LOW
Revive Adserver 6.0.0-6.0.3 - Format String Injection in Settings
CVSS 2.7
Details
Vulnerabilities
399
Exploit Likelihood
High