CWE-822: CWE-822

81
Total CVEs
6
Critical
63
High
7.7
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
15
2025
33
2024
25
2023
5
2022
1

Top Affected Vendors

1 Microsoft 42
2 Qualcomm 13
3 Intel 3
4 Nvidia 3
5 Ashlar 3
6 Rti 2
7 Codesys 1
8 Samsung 1
9 Autodesk 1
10 Advantech 1

All CWE-822 CVEs (81)

CVE-2025-50165
9.8

This critical vulnerability in Microsoft Graphics Component allows remote attackers to execute arbitrary code by exploiting an untrusted pointer deref...

Aug 12, 2025
CVE-2023-1437
9.8

This vulnerability in Advantech WebAccess/SCADA allows attackers to send malicious RPC arguments containing raw memory pointers that the server uses w...

Aug 2, 2023
CVE-2025-4993
9.1

CVE-2025-4993 is an untrusted pointer dereference vulnerability in RTI Connext Professional Core Libraries that allows attackers to manipulate pointer...

Sep 23, 2025
CVE-2025-1255
9.1

CVE-2025-1255 is an untrusted pointer dereference vulnerability in RTI Connext Professional Core Libraries that allows attackers to manipulate pointer...

Sep 23, 2025
CVE-2024-36461
9.1

CVE-2024-36461 is a critical memory corruption vulnerability in Zabbix's JavaScript engine that allows authenticated users to directly modify memory p...

Aug 12, 2024
CVE-2023-21643
9.1

CVE-2023-21643 is a memory corruption vulnerability in Qualcomm automotive systems caused by untrusted pointer dereference during system calls. This a...

Aug 8, 2023
CVE-2024-37339
8.8

This vulnerability in Microsoft SQL Server's Native Scoring component allows authenticated attackers to execute arbitrary code remotely. It affects SQ...

Sep 10, 2024
CVE-2024-38104
8.8

CVE-2024-38104 is a remote code execution vulnerability in the Windows Fax Service that allows an attacker to execute arbitrary code with SYSTEM privi...

Jul 9, 2024
CVE-2023-0189
8.8

This vulnerability in NVIDIA GPU Display Driver for Linux allows attackers to exploit a kernel mode layer handler flaw, potentially leading to code ex...

Apr 1, 2023
CVE-2024-36352
8.4

An improper input validation vulnerability in AMD Graphics Drivers allows attackers to supply specially crafted pointers, potentially leading to arbit...

Sep 6, 2025
CVE-2025-20018
8.4

This vulnerability in Intel Graphics Drivers allows an authenticated local user to potentially escalate privileges by exploiting an untrusted pointer ...

May 13, 2025
CVE-2025-24084
8.4

CVE-2025-24084 is an untrusted pointer dereference vulnerability in Windows Subsystem for Linux that allows local attackers to execute arbitrary code ...

Mar 11, 2025
CVE-2025-21354
8.4

This vulnerability allows remote code execution through specially crafted Excel files. Attackers can exploit this by tricking users into opening malic...

Jan 14, 2025
CVE-2024-34023
8.4

This vulnerability involves an untrusted pointer dereference in certain Intel Graphics Drivers, allowing an authenticated user with local access to po...

Nov 13, 2024
CVE-2024-40872
8.4

This vulnerability allows attackers with local access and valid desktop user credentials to elevate their privileges to SYSTEM level by passing invali...

Jul 25, 2024
CVE-2023-43532
8.4

This vulnerability allows memory corruption when reading ACPI configuration through user mode applications on Qualcomm chipsets. Attackers could poten...

Feb 6, 2024
CVE-2024-37969
8.0

This vulnerability allows attackers to bypass Secure Boot protections on affected systems, potentially enabling them to load and execute unauthorized ...

Jul 9, 2024
CVE-2026-21250
7.8

CVE-2026-21250 is a local privilege escalation vulnerability in Windows HTTP.sys driver where an authorized attacker can exploit untrusted pointer der...

Feb 10, 2026
CVE-2026-21232
7.8

CVE-2026-21232 is an untrusted pointer dereference vulnerability in Windows HTTP.sys that allows an authenticated attacker to escalate privileges loca...

Feb 10, 2026
CVE-2026-20955
7.8

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an untrusted pointer dereference in Microsoft Excel...

Jan 13, 2026
CVE-2026-20956
7.8

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an untrusted pointer dereference in Microsoft Excel...

Jan 13, 2026
CVE-2026-20948
7.8

This vulnerability allows an unauthorized attacker to execute arbitrary code on a local system by exploiting an untrusted pointer dereference in Micro...

Jan 13, 2026
CVE-2026-20940
7.8

A heap-based buffer overflow vulnerability in the Windows Cloud Files Mini Filter Driver allows authenticated attackers to execute arbitrary code with...

Jan 13, 2026
CVE-2026-20938
7.8

CVE-2026-20938 is an untrusted pointer dereference vulnerability in Windows Virtualization-Based Security (VBS) Enclave that allows an authenticated a...

Jan 13, 2026
CVE-2026-20857
7.8

This vulnerability allows an authorized attacker to exploit an untrusted pointer dereference in the Windows Cloud Files Mini Filter Driver to elevate ...

Jan 13, 2026
CVE-2026-20811
7.8

This vulnerability is a type confusion flaw in Windows Win32K - ICOMP that allows an authenticated attacker to escalate privileges locally. It affects...

Jan 13, 2026
CVE-2025-47380
7.8

This vulnerability involves memory corruption in sensor IOCTL preprocessing, allowing attackers to potentially execute arbitrary code or cause system ...

Jan 7, 2026
CVE-2025-47343
7.8

This CVE describes a memory corruption vulnerability in Qualcomm video processing components that could allow attackers to execute arbitrary code or c...

Jan 7, 2026
CVE-2025-47387
7.8

This vulnerability allows memory corruption when processing JPEG data through IOCTL calls without proper validation. Attackers could potentially execu...

Dec 18, 2025
CVE-2025-62200
7.8

This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an untrusted pointer dereference in Microsoft Excel...

Nov 11, 2025
CVE-2025-60713
7.8

CVE-2025-60713 is a local privilege escalation vulnerability in Windows Routing and Remote Access Service (RRAS) where an authenticated attacker can e...

Nov 11, 2025
CVE-2025-60703
7.8

This vulnerability allows an authorized attacker to exploit an untrusted pointer dereference in Windows Remote Desktop to elevate privileges locally. ...

Nov 11, 2025
CVE-2025-55677
7.8

This vulnerability allows an authorized attacker to exploit an untrusted pointer dereference in the Windows Device Association Broker service to eleva...

Oct 14, 2025
CVE-2025-24990
KEV 7.8

This CVE describes an elevation of privilege vulnerability in the Agere Modem driver (ltmdm64.sys) that ships with Windows. Attackers could exploit th...

Oct 14, 2025
CVE-2025-47338
7.8

This vulnerability allows memory corruption when processing escape commands from userspace, potentially leading to arbitrary code execution or system ...

Oct 9, 2025
CVE-2025-27048
7.8

This vulnerability allows attackers to cause memory corruption through improper handling of IOCTL calls in Qualcomm camera platform drivers. Successfu...

Oct 9, 2025
CVE-2025-55230
7.8

This vulnerability allows an authenticated attacker to exploit an untrusted pointer dereference in the Windows MBT Transport driver to gain elevated l...

Aug 21, 2025
CVE-2025-27069
7.8

This vulnerability allows memory corruption when processing DDI command calls in Qualcomm components, potentially enabling attackers to execute arbitr...

Aug 6, 2025
CVE-2025-49661
7.8

This vulnerability allows an authorized attacker to exploit an untrusted pointer dereference in the Windows Ancillary Function Driver for WinSock to e...

Jul 8, 2025
CVE-2025-27747
7.8

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on affected systems by tricking users into opening ...

Apr 8, 2025
CVE-2025-27739
7.8

This Windows kernel vulnerability allows an authenticated attacker to exploit untrusted pointer dereference to gain elevated local privileges. It affe...

Apr 8, 2025
CVE-2025-24083
7.8

CVE-2025-24083 is an untrusted pointer dereference vulnerability in Microsoft Office that allows local attackers to execute arbitrary code by exploiti...

Mar 11, 2025
CVE-2024-53033
7.8

This vulnerability allows memory corruption in Qualcomm components when a malicious user provides a kernel address instead of a valid user buffer addr...

Mar 3, 2025
CVE-2025-21381
7.8

Microsoft Excel contains a remote code execution vulnerability that allows attackers to execute arbitrary code by tricking users into opening speciall...

Feb 11, 2025
CVE-2025-21358
7.8

This Windows Core Messaging vulnerability allows attackers to elevate privileges on affected systems. An authenticated attacker could exploit this to ...

Feb 11, 2025
CVE-2024-45584
7.8

This vulnerability allows memory corruption when userspace makes a compat IOCTL call followed by a normal IOCTL call, potentially leading to privilege...

Feb 3, 2025
CVE-2025-21363
7.8

This vulnerability allows remote code execution when a user opens a specially crafted Microsoft Word document. Attackers could gain full control of af...

Jan 14, 2025
CVE-2024-49090
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM-level privileges on affected sy...

Dec 12, 2024
CVE-2024-43516
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code in Windows Secure Kernel Mode, potentially gaining SYSTEM privileges. It...

Oct 8, 2024
CVE-2024-21455
7.8

This vulnerability allows memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a Qualcomm driver. Attackers ...

Oct 7, 2024

About CWE-822 (CWE-822)

Our database tracks 81 CVEs classified as CWE-822, with 6 rated critical and 63 rated high severity. The average CVSS score for CWE-822 vulnerabilities is 7.7.

External reference: View CWE-822 on MITRE CWE →

Monitor CWE-822 Vulnerabilities

Get alerted when new CWE-822 CVEs affect your infrastructure.

Start Monitoring Free