VulnSea

CWE-822

CVEs classified under CWE-822, newest first.

48 CVEsRSS

CVE-2026-94403High· 8.8
yesterday

A weakness has been identified in ColorFul iGameCenter 1.0.3.4

A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be…

TwilightColorFul · iGameCentervia NVD
CVE-2026-25261Medium· 6.7
5d ago

Memory corruption while processing rear sensor IOCTL calls.

Memory corruption while processing rear sensor IOCTL calls.

SunlitQualcomm, Inc. · SnapdragonEPSS 0.11%via NVD
CVE-2025-59607High· 7.8
5d ago

Memory Corruption when copying large input data exceeds normal allocation limits.

Memory Corruption when copying large input data exceeds normal allocation limits.

TwilightQualcomm, Inc. · SnapdragonEPSS 0.11%via NVD
CVE-2026-33964Medium· 6.4
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500

An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.

SunlitSamsung · Exynos 1580 firmwareEPSS 0.10%via NVD
CVE-2026-90890Medium· 5.5
1w ago

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unval…

SunlitASRock · ASRock Polychrome SYNC/RGB for MBEPSS 0.10%via NVD
CVE-2026-89489Medium· 5.5⚖ disputed
1w ago

kernel: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall (CVE-2026-89489)

A flaw was found in the Linux kernel. The `sys_or1k_atomic()` syscall, specific to the openrisc architecture, does not adequately validate user-provided pointers. An unprivileged process can exploit this by supplying kernel addresses to th…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.14%via CSAF
CVE-2026-83939High· 8.2
2w ago

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_11_26h1EPSS 0.30%via NVD
CVE-2026-83498High· 7.8
2w ago

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_11_23h2EPSS 0.30%via NVD
CVE-2026-80083High· 8.8
2w ago

Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.

Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.

Twilightmicrosoft · windows_11_23h2EPSS 0.23%via NVD
CVE-2026-78451Medium· 6.8
2w ago

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

Sunlitmicrosoft · windows_10_1809EPSS 0.44%via NVD
CVE-2026-78444High· 8.1
2w ago

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · windows_10_1809EPSS 0.51%via NVD
CVE-2026-72956Medium· 6.5
2w ago

Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sunlitmicrosoft · 365_appsEPSS 0.92%via NVD
CVE-2026-72938Medium· 6.5
2w ago

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sunlitmicrosoft · 365_appsEPSS 0.92%via NVD
CVE-2026-69900High· 7.8
2w ago

Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_21h2EPSS 0.30%via NVD
CVE-2026-69874High· 8.2
2w ago

Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1809EPSS 0.26%via NVD
CVE-2026-69717High· 8.0
2w ago

Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.70%via NVD
CVE-2026-69569Medium· 5.7
2w ago

Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.

Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.

Sunlitmicrosoft · windows_10_1607EPSS 0.86%via NVD
CVE-2026-69501High· 7.0
2w ago

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_21h2EPSS 0.24%via NVD
CVE-2026-69475High· 7.8
2w ago

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.31%via NVD
CVE-2026-67378Critical· 9.0
2w ago

Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.

Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.

Midnightmicrosoft · sql_server_2019EPSS 0.51%via NVD
CVE-2026-82927Medium· 5.5
3w ago

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.

SunlitSamsung Open Source · mTowerEPSS 0.11%via CVEORG
CVE-2026-10420Medium· 5.5
3w ago

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.

SunlitSamsung Open Source · mTowerEPSS 0.11%via CVEORG
CVE-2026-8917High· 8.4
1mo ago

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation.…

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation.…

TwilightASUS · GPU Tweak IIIEPSS 0.11%via NVD
CVE-2026-62737High· 7.8PoC
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

MidnightMicrosoft · Windows 11 Version 24H2EPSS 2.8%via CVEORG
CVE-2026-62798Medium· 5.5
1mo ago

Win32k Information Disclosure Vulnerability

Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 11 version 23H2EPSS 0.31%via CVEORG
CVE-2026-68810High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.30%via CVEORG
CVE-2026-64910High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.34%via CVEORG
CVE-2026-61360Medium· 5.5
1mo ago

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.39%via NVD
CVE-2026-7406High· 7.8
1mo ago

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the cur…

Twilightautodesk · advance_steelEPSS 0.13%via NVD
CVE-2026-15029High· 8.4
2mo ago

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req…

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req…

TwilightASUS · System Control Interface v3EPSS 0.17%via NVD
CWE-822 vulnerabilities (CVEs) · VulnSea