CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

373 vulnerabilities with CWE-134
CVE-2026-0400 MEDIUM
SonicOS - Format String DoS
CVSS 4.9
CVE-2025-30269 HIGH
Qsync Central <5.0.0.4 - Memory Corruption
CVSS 8.1
CVE-2025-64157 MEDIUM
Fortinet Fortios < 7.4.10 - Format String Vulnerability
CVSS 6.7
CVE-2026-21640 LOW
Aquaplatform Revive Adserver < 6.0.4 - Format String Vulnerability
CVSS 2.7
CVE-2025-68949 MEDIUM
n8n <2.2.0 - Info Disclosure
CVSS 5.3
CVE-2026-22190 HIGH
CMU Panda3d < 1.10.16 - Format String Vulnerability
CVSS 7.5
CVE-2025-53591 MEDIUM
QNAP OS - Info Disclosure
CVSS 6.5
CVE-2023-53966 CRITICAL
SOUND4 LinkAndShare Transmitter 1.1.2 - Memory Corruption
CVSS 9.8
CVE-2025-52666 LOW
Revive-adserver Revive Adserver < 5.5.2 - Format String Vulnerability
CVSS 2.7
CVE-2025-48826 HIGH
Planet WGR-500 <1.3411b190912 - Memory Corruption
CVSS 8.8
CVE-2025-53407 MEDIUM
QNAP OS - Info Disclosure
CVSS 6.5
CVE-2025-53406 MEDIUM
QNAP OS - Info Disclosure
CVSS 6.5
CVE-2025-52429 MEDIUM
Qnap Qts - Format String Vulnerability
CVSS 6.5
CVE-2025-48730 MEDIUM
QNAP OS - Info Disclosure
CVSS 6.5
CVE-2025-36202 HIGH
IBM Webmethods Integration - Format String Vulnerability
CVSS 7.5
CVE-2010-10017
WM Downloader 3.1.2.2 - Buffer Overflow
CVE-2025-55298 HIGH
ImageMagick <6.9.13-28 & <7.1.2 - RCE
CVSS 7.5
CVE-2011-10029
Solar FTP Server - DoS
CVE-2012-10055
ComSndFTP FTP Server <1.3.7 Beta - Code Injection
CVE-2025-40600 CRITICAL
Sonicwall Sonicos < 7.3.0-7012 - Format String Vulnerability
CVSS 9.8
CVE-2025-46123 HIGH
Ruckuswireless Ruckus Unleashed - Format String Vulnerability
CVSS 7.2
CVE-2025-46121 CRITICAL
Ruckuswireless Ruckus Unleashed - Format String Vulnerability
CVSS 9.8
CVE-2025-22482 HIGH
Qnap Qsync Central < 4.5.0.6 - Format String Vulnerability
CVSS 8.1
CVE-2025-48388 MEDIUM
FreeScout <1.8.178 - Code Injection
CVSS 6.5
CVE-2024-45324 HIGH
FortiOS <6.4.15 - Memory Corruption
CVSS 7.2
Details
Vulnerabilities 373
Exploit Likelihood High