CWE-822: CWE-822

81
Total CVEs
6
Critical
63
High
7.7
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
15
2025
33
2024
25
2023
5
2022
1

Top Affected Vendors

1 Microsoft 42
2 Qualcomm 13
3 Intel 3
4 Nvidia 3
5 Ashlar 3
6 Rti 2
7 Codesys 1
8 Samsung 1
9 Autodesk 1
10 Advantech 1

All CWE-822 CVEs (81)

CVE-2024-38187
7.8

This vulnerability allows an authenticated attacker to exploit a flaw in a Windows kernel-mode driver to gain SYSTEM-level privileges. It affects Wind...

Aug 13, 2024
CVE-2024-38185
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a flaw in the Windows kernel-mode d...

Aug 13, 2024
CVE-2024-0091
7.8

This vulnerability in NVIDIA GPU Display Drivers allows users to cause untrusted pointer dereference through driver API execution. Successful exploita...

Jun 13, 2024
CVE-2024-35250
7.8

This vulnerability allows attackers to gain elevated privileges on Windows systems by exploiting a flaw in a kernel-mode driver. It affects Windows op...

Jun 11, 2024
CVE-2023-40471
7.8

PDF-XChange Editor contains an untrusted pointer dereference vulnerability that allows remote code execution when users open malicious PDF files or vi...

May 3, 2024
CVE-2023-34309
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious CO...

May 3, 2024
CVE-2023-34311
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious CO...

May 3, 2024
CVE-2023-34301
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CO files or visiting malicious web pages...

May 3, 2024
CVE-2024-21338
7.8

CVE-2024-21338 is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM priv...

Feb 13, 2024
CVE-2023-34332
7.8

This vulnerability in AMI's SPx BMC allows attackers on the local network to exploit an untrusted pointer dereference, potentially compromising the Ba...

Jan 9, 2024
CVE-2023-41139
7.8

A maliciously crafted STP file can trigger an untrusted pointer dereference vulnerability in Autodesk AutoCAD 2024 and 2023. This could allow an attac...

Nov 23, 2023
CVE-2023-25515
7.8

This vulnerability in NVIDIA GPU display drivers allows attackers to execute arbitrary code, escalate privileges, or cause denial of service by sendin...

Jun 23, 2023
CVE-2021-38401
7.8

This vulnerability in Fuji Electric V-Server Lite and Tellus Lite V-Simulator allows attackers to execute arbitrary code by exploiting an untrusted po...

Dec 20, 2021
CVE-2024-26254
7.5

This vulnerability in Microsoft's Virtual Machine Bus (VMBus) allows an attacker to cause a denial of service condition on affected systems. It affect...

Apr 9, 2024
CVE-2020-1899
7.5

CVE-2020-1899 is a memory corruption vulnerability in HHVM's unserialize() function that allows accessing arbitrary memory addresses via the 'S' type ...

Mar 11, 2021
CVE-2024-43553
7.4

This CVE describes a Windows NT kernel elevation of privilege vulnerability that allows authenticated attackers to gain SYSTEM-level privileges on aff...

Oct 8, 2024
CVE-2024-43529
7.3

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the Print Spooler service. Attackers could gain SYSTEM-leve...

Oct 8, 2024
CVE-2022-22514
7.1

CVE-2022-22514 is a memory corruption vulnerability in CODESYS Control runtime systems that allows authenticated remote attackers to cause denial of s...

Apr 7, 2022
CVE-2025-60719
7.0

This vulnerability allows an authorized attacker to exploit an untrusted pointer dereference in the Windows Ancillary Function Driver for WinSock to e...

Nov 11, 2025
CVE-2024-33039
6.7

This vulnerability allows memory corruption when a PAL client passes random values as handles to PAL service APIs without proper validation. It affect...

Dec 2, 2024
CVE-2024-37982
6.7

This vulnerability allows attackers to bypass security features in Windows Resume Extensible Firmware Interface (Resume EFI) during system resume oper...

Oct 8, 2024
CVE-2025-47325
6.5

This vulnerability allows attackers to access sensitive information by exploiting improper handling of system calls with invalid parameters. It affect...

Dec 18, 2025
CVE-2025-60708
6.5

CVE-2025-60708 is an untrusted pointer dereference vulnerability in the Storvsp.sys driver that allows an authenticated attacker to cause a local deni...

Nov 11, 2025
CVE-2025-32446
6.5

An untrusted pointer dereference vulnerability in Intel QuickAssist Technology software before version 2.6.0 allows authenticated local users to escal...

Nov 11, 2025
CVE-2025-27710
6.5

This vulnerability in Intel QAT Windows software allows authenticated local users to potentially read sensitive information from memory. It affects sy...

Nov 11, 2025
CVE-2026-20935
6.2

This vulnerability allows an unauthorized local attacker to read sensitive information from Windows Virtualization-Based Security (VBS) Enclave memory...

Jan 13, 2026
CVE-2025-52516
6.2

A kernel address dereference vulnerability in the issimian device driver for Samsung Exynos processors allows attackers to cause denial of service. Th...

Jan 5, 2026
CVE-2023-32277
6.1

This vulnerability allows authenticated local users to potentially disclose sensitive information through an untrusted pointer dereference in Intel QA...

Feb 12, 2025
CVE-2025-59959
5.5

A local untrusted pointer dereference vulnerability in Juniper Junos OS routing protocol daemon allows authenticated low-privilege users to cause deni...

Jan 15, 2026
CVE-2026-20819
5.5

This vulnerability allows an authorized attacker to exploit an untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave to...

Jan 13, 2026
CVE-2025-20090
5.5

This CVE describes an untrusted pointer dereference vulnerability in Intel QuickAssist Technology software that could allow an authenticated user with...

Aug 12, 2025

About CWE-822 (CWE-822)

Our database tracks 81 CVEs classified as CWE-822, with 6 rated critical and 63 rated high severity. The average CVSS score for CWE-822 vulnerabilities is 7.7.

External reference: View CWE-822 on MITRE CWE →

Monitor CWE-822 Vulnerabilities

Get alerted when new CWE-822 CVEs affect your infrastructure.

Start Monitoring Free