CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

399 vulnerabilities with CWE-134
CVE-2026-22190 HIGH
Panda3D <= 1.10.16 - Information Disclosure via egg-mkfont Glyph Pattern Format String
CVSS 7.5
CVE-2025-10262 MEDIUM
Nokia SR Linux - Authenticated Local Privilege Escalation
CVSS 6.3
CVE-2025-68648 HIGH
Fortinet FortiAnalyzer/FortiManager - Memory Corruption
CVSS 7.2
CVE-2025-30269 HIGH
Qsync Central <5.0.0.4 - Memory Corruption
CVSS 8.1
CVE-2025-64157 MEDIUM
FortiOS 7.0-7.6.4 - Authenticated Use of Externally-Controlled Format String via Configuration
CVSS 6.7
CVE-2025-68949 MEDIUM
n8n 1.36.0-2.1.9 - IP Whitelist Bypass via Partial String Matching
CVSS 5.3
CVE-2025-53591 MEDIUM
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 6.5
CVE-2025-52666 LOW
Revive Adserver < 5.5.2 - Authenticated Format String Injection in Admin Settings
CVSS 2.7
CVE-2025-48826 HIGH
Planet WGR-500 <1.3411b190912 - Memory Corruption
CVSS 8.8
CVE-2025-53407 MEDIUM
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 6.5
CVE-2025-53406 MEDIUM
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 6.5
CVE-2025-52429 MEDIUM
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 6.5
CVE-2025-48730 MEDIUM
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 6.5
CVE-2025-36202 HIGH
IBM webMethods Integration 10.15 and 11.1 - Authenticated Command Execution via Format String Vulnerability
CVSS 7.5
CVE-2025-55298 HIGH
ImageMagick <6.9.13-28 & <7.1.2 - RCE
CVSS 7.5
CVE-2025-40600 CRITICAL
SonicOS 7.1.1-7040 to <7.3.0-7012 - Unauthenticated Denial of Service via Format String
CVSS 9.8
CVE-2025-46123 HIGH
Ruckus Unleashed <200.15.6.212.14 & ZoneDirector <10.5.1.0.279 - Authenticated RCE via Format String
CVSS 7.2
CVE-2025-46121 CRITICAL
Ruckus Unleashed < 200.15.6.212.14 and 200.17.7.0.139 - Unauthenticated Format String Injection via DHCP Hostname
CVSS 9.8
CVE-2025-22482 HIGH
Qsync Central 4.5.0.3-4.5.0.5 - Authenticated Use of Externally-Controlled Format String
CVSS 8.1
CVE-2025-48388 MEDIUM
FreeScout <1.8.178 - Code Injection
CVSS 6.5
CVE-2025-24359 HIGH
asteval < 1.0.6 - Remote Code Execution via FormattedValue AST Node Handling
CVSS 8.4
CVE-2024-58366 HIGH
SurrealDB before 1.1.1 Format String via Scripting Functions
CVSS 8.5
CVE-2024-45324 HIGH
FortiOS <6.4.15 - Memory Corruption
CVSS 7.2
CVE-2024-55156 MEDIUM
Java SDK for CloudEvents <4.0.1 - XSS
CVSS 5.5
CVE-2024-12805 HIGH
SonicOS < 6.5.4.15-117n, < 7.0.1-5161, < 7.1.2-7019, < 8.0.0-8035 - Authenticated Format String Vulnerability
CVSS 7.2
Details
Vulnerabilities 399
Exploit Likelihood High