CWE-822 · 240 records
Untrusted Pointer Dereference
CVEs in this class
240 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
79This week | CVE-2024-21338Weaponized | Windows Kernel Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-822 | High7.8 | KEV | 59.8% | Feb 13, 2024 |
69This week | CVE-2024-35250Weaponized | Windows Kernel-Mode Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-822 | High7.8 | KEV | 25.2% | Jun 11, 2024 |
69This week | CVE-2023-29360Weaponized | Microsoft Streaming Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-822 | High8.4 | KEV | 21.6% | Jun 13, 2023 |
65This week | CVE-2023-36033Weaponized | Windows DWM Core Library Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-822 | High7.8 | KEV | 12.0% | Nov 14, 2023 |
63This week | CVE-2025-24990Weaponized | Windows Agere Modem Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-822 | High7.8 | KEV | 6.4% | Oct 14, 2025 |
51Plan | CVE-2023-21768Weaponized | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilitymicrosoft · windows 11 · CWE-822 | High7.8 | — | 65.4% | Jan 10, 2023 |
42Plan | CVE-2025-50165Proof of concept | Windows Graphics Component Remote Code Execution Vulnerabilitymicrosoft · windows 11 24h2 · CWE-822 | Critical9.8 | — | 10.3% | Aug 12, 2025 |
41Plan | CVE-2018-17893No exploit | LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.lcds · laquis scada · CWE-822 | Critical9.8 | — | 6.4% | Oct 16, 2018 |
40Plan | CVE-2018-14811No exploit | Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, which may allow remotfujielectric · v-server firmware · CWE-822 | Critical9.8 | — | 3.6% | Sep 26, 2018 |
40Plan | CVE-2018-7497No exploit | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioadvantech · webaccess · CWE-822 | Critical9.8 | — | 2.8% | May 15, 2018 |
40Plan | CVE-2023-1437No exploit | All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers.advantech · webaccess\/scada · CWE-822 | Critical9.8 | — | 2.8% | Aug 2, 2023 |
39Monitor | CVE-2018-12548No exploit | In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives whicheclipse · openj9 · CWE-822 | Critical9.8 | — | 1.1% | Jan 31, 2019 |
39Monitor | CVE-2023-43518No exploit | Untrusted Pointer Dereference in Videoqualcomm · aqt1000 firmware · CWE-822 | Critical9.8 | — | 0.3% | Feb 6, 2024 |
37Monitor | CVE-2026-48137No exploit | Untrusted pointer dereference in NI grpc-device sideband streaming APIni · instrumentstudio · CWE-822 | Critical9.3 | — | 0.8% | Jun 19, 2026 |
37Monitor | CVE-2026-103764No exploit | Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated atCWE-822 | Critical9.3 | — | — | Today |
36Monitor | CVE-2020-26991No exploit | A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2).siemens · jt2go · CWE-822 | High8.8 | — | 4.0% | Jan 12, 2021 |
36Monitor | CVE-2020-27259No exploit | The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attackeromron · cx-one · CWE-822 | High8.8 | — | 2.7% | Feb 9, 2021 |
36Monitor | CVE-2024-43624No exploit | Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-822 | High8.8 | — | 1.8% | Nov 12, 2024 |
36Monitor | CVE-2024-38104No exploit | Windows Fax Service Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-822 | High8.8 | — | 1.8% | Jul 9, 2024 |
36Monitor | CVE-2026-67378No exploit | Microsoft SQL Server Remote Code Execution Vulnerabilitymicrosoft · sql server 2019 · CWE-822 | Critical9.0 | — | 0.7% | Sep 8, 2026 |
35Monitor | CVE-2024-37340No exploit | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerabilitymicrosoft · sql 2016 azure connect feature pack · CWE-822 | High8.8 | — | 1.6% | Sep 10, 2024 |
35Monitor | CVE-2024-37339No exploit | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerabilitymicrosoft · sql 2016 azure connect feature pack · CWE-822 | High8.8 | — | 1.6% | Sep 10, 2024 |
35Monitor | CVE-2025-62549No exploit | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-822 | High8.8 | — | 1.3% | Dec 9, 2025 |
35Monitor | CVE-2026-33120No exploit | Microsoft SQL Server Remote Code Execution Vulnerabilitymicrosoft · sql server 2016 · CWE-822 | High8.8 | — | 0.9% | Apr 14, 2026 |
35Monitor | CVE-2024-36461No exploit | Direct access to memory pointers within the JS engine for modificationzabbix · zabbix · CWE-822 | High8.8 | — | 0.8% | Aug 12, 2024 |
- CVE-2024-2133879This week
Windows Kernel Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 60%microsoft · windows 10 1809Feb 13, 2024
- CVE-2024-3525069This week
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 25%microsoft · windows 10 1507Jun 11, 2024
- CVE-2023-2936069This week
Microsoft Streaming Service Elevation of Privilege Vulnerability
HighCVSS 8.4KEVWeaponizedEPSS 22%microsoft · windows 10 1607Jun 13, 2023
- CVE-2023-3603365This week
Windows DWM Core Library Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 12%microsoft · windows 10 1809Nov 14, 2023
- CVE-2025-2499063This week
Windows Agere Modem Driver Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 6%microsoft · windows 10 1507Oct 14, 2025
- CVE-2023-2176851Plan
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
HighCVSS 7.8WeaponizedEPSS 65%microsoft · windows 11Jan 10, 2023
- CVE-2025-5016542Plan
Windows Graphics Component Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 10%microsoft · windows 11 24h2Aug 12, 2025
- CVE-2018-1789341Plan
LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.
CriticalCVSS 9.8No exploitEPSS 6%lcds · laquis scadaOct 16, 2018
- CVE-2018-1481140Plan
Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, which may allow remot
CriticalCVSS 9.8No exploitEPSS 4%fujielectric · v-server firmwareSep 26, 2018
- CVE-2018-749740Plan
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prio
CriticalCVSS 9.8No exploitEPSS 3%advantech · webaccessMay 15, 2018
- CVE-2023-143740Plan
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers.
CriticalCVSS 9.8No exploitEPSS 3%advantech · webaccess\/scadaAug 2, 2023
- CVE-2018-1254839Monitor
In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which
CriticalCVSS 9.8No exploitEPSS 1%eclipse · openj9Jan 31, 2019
- CVE-2023-4351839Monitor
Untrusted Pointer Dereference in Video
CriticalCVSS 9.8No exploitEPSS 0%qualcomm · aqt1000 firmwareFeb 6, 2024
- CVE-2026-4813737Monitor
Untrusted pointer dereference in NI grpc-device sideband streaming API
CriticalCVSS 9.3No exploitEPSS 1%ni · instrumentstudioJun 19, 2026
- CVE-2026-10376437Monitor
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated at
CriticalCVSS 9.3No exploitToday
- CVE-2020-2699136Monitor
A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2).
HighCVSS 8.8No exploitEPSS 4%siemens · jt2goJan 12, 2021
- CVE-2020-2725936Monitor
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker
HighCVSS 8.8No exploitEPSS 3%omron · cx-oneFeb 9, 2021
- CVE-2024-4362436Monitor
Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 2%microsoft · windows 10 1809Nov 12, 2024
- CVE-2024-3810436Monitor
Windows Fax Service Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 2%microsoft · windows 10 1507Jul 9, 2024
- CVE-2026-6737836Monitor
Microsoft SQL Server Remote Code Execution Vulnerability
CriticalCVSS 9.0No exploitEPSS 1%microsoft · sql server 2019Sep 8, 2026
- CVE-2024-3734035Monitor
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 2%microsoft · sql 2016 azure connect feature packSep 10, 2024
- CVE-2024-3733935Monitor
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 2%microsoft · sql 2016 azure connect feature packSep 10, 2024
- CVE-2025-6254935Monitor
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · windows 10 1607Dec 9, 2025
- CVE-2026-3312035Monitor
Microsoft SQL Server Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · sql server 2016Apr 14, 2026
- CVE-2024-3646135Monitor
Direct access to memory pointers within the JS engine for modification
HighCVSS 8.8No exploitEPSS 1%zabbix · zabbixAug 12, 2024