Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-822

MITRE ↗

CWE-822

1
CRITICAL
46
HIGH
10
MEDIUM
63 CVEs · Page 1/2
9.1
CVE-2026-48137

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an a

8.8
CVE-2026-33120

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

8.8
CVE-2026-50382

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

8.8
CVE-2026-9771

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USE

8.4
CVE-2026-26113

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-33114

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-40367

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t

8.4
CVE-2026-12364

The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through

8.3
CVE-2026-58596

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges o

8.2
CVE-2026-18840

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper val

8.2
CVE-2026-19442

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initi

7.8
CVE-2025-47343

Memory corruption while processing a video session to set video parameters.

7.8
CVE-2025-47380

Memory corruption while preprocessing IOCTLs in sensors.

7.8
CVE-2026-20811

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to

7.8
CVE-2026-20857

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privile

7.8
CVE-2026-20938

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to el

7.8
CVE-2026-20940

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges

7.8
CVE-2026-20948

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-20955

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-20956

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-21232

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-21250

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-26112

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-26161

Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally

7.8
CVE-2026-27919

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele

7.8
CVE-2026-27920

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele

7.8
CVE-2026-32077

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele

7.8
CVE-2026-32222

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-47405

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

7.8
CVE-2025-47408

Memory corruption when another driver calls an IOCTL with invalid input/output buffer.

7.8
CVE-2026-40369

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-45471

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-45643

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-45645

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50367

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to e

7.8
CVE-2026-50441

Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privilege

7.8
CVE-2026-50479

Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-55136

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-48340

Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in th

7.8
CVE-2026-24083

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

7.8
CVE-2026-7406

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference

7.8
CVE-2026-45198

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G

7.8
CVE-2026-62737

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-64910

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68810

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.5
CVE-2026-50424

Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a networ

7.3
CVE-2026-8835

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Admin

6.2
CVE-2025-52516

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400,

6.2
CVE-2026-20935

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to

5.7
CVE-2026-23670

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to by

Frequently Asked Questions

What is CWE-822?

CWE-822 (CWE-822) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-822?

There are 63 CVE records associated with CWE-822 in our database. Of these, 1 are critical severity, 46 are high severity, and 10 are medium severity.

How can I protect against CWE-822 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-822 using AI-powered security agents.

Detect CWE-822 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-822 vulnerabilities across your infrastructure.

Get Started