VulnSea

CWE-822

CVEs classified under CWE-822, newest first.

64 CVEsRSS

CVE-2026-61360Medium· 5.5
1mo ago

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.40%via NVD
CVE-2026-7406High· 7.8
1mo ago

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the cur…

▾ Twilightautodesk · advance_steelEPSS 0.19%via NVD
CVE-2026-15029High· 8.4
2mo ago

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req…

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req…

▾ TwilightASUS · System Control Interface v3EPSS 0.17%via NVD
CVE-2026-50382High· 8.8
2mo ago

DirectX Graphics Kernel Remote Code Execution Vulnerability

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-50441High· 7.8
2mo ago

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50367High· 7.8
2mo ago

Windows Sensor Data Service Elevation of Privilege Vulnerability

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-50424High· 7.5
2mo ago

Windows Domain Controller Denial of Service Vulnerability

Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 1.2%via CVEORG
CVE-2026-48580Medium· 5.5
2mo ago

Microsoft Excel Information Disclosure Vulnerability

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-55138Medium· 5.5
2mo ago

Microsoft Excel Information Disclosure Vulnerability

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-55136High· 7.8
2mo ago

Microsoft Excel Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-50479High· 7.8
2mo ago

Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via NVD
CVE-2026-58596High· 8.3
2mo ago

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via NVD
CVE-2026-45471High· 7.8
3mo ago

Microsoft Word Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.57%via CVEORG
CVE-2026-45645High· 7.8
3mo ago

Microsoft Office Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-45643High· 7.8
3mo ago

Microsoft Word Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-44805Medium· 5.5
3mo ago

Windows Network Controller (NC) Host Agent Denial of Service Vulnerability

Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.

▾ SunlitMicrosoft · Windows Server 2019EPSS 0.40%via CVEORG
CVE-2026-40369High· 7.8PoC
4mo ago

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ MidnightEPSS 0.33%via NVD
CVE-2026-23670Medium· 5.7
5mo ago

Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.27%via CVEORG
CVE-2026-26161High· 7.8
5mo ago

Windows Sensor Data Service Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-27919High· 7.8
5mo ago

Windows UPnP Device Host Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-33120High· 8.8
5mo ago

Microsoft SQL Server Remote Code Execution Vulnerability

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SQL Server 2022 (GDR)EPSS 0.91%via CVEORG
CVE-2026-27920High· 7.8
5mo ago

Windows UPnP Device Host Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-32077High· 7.8
5mo ago

Windows UPnP Device Host Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.41%via CVEORG
CVE-2026-33114High· 8.4
5mo ago

Microsoft Word Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.36%via CVEORG
CVE-2026-32222High· 7.8
5mo ago

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.33%via NVD
CVE-2026-31411Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc p…

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc p…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-20857High· 7.8
8mo ago

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.48%via NVD
CVE-2026-20819Medium· 5.5
8mo ago

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_11_23h2EPSS 0.55%via NVD
CVE-2026-20811High· 7.8
8mo ago

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_23h2EPSS 0.49%via NVD
CVE-2025-4993Critical· 9.1
1y ago

Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation

Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, from 6.1.0 before 6.1.2.2…

▾ Midnightrti · connext_professionalEPSS 0.37%via NVD
CWE-822 vulnerabilities (CVEs) — page 2 · VulnSea