Skip to main content

CWE archive

CWE-782 CVEs

Programmatic archive

40 CVEs tagged with CWE-7824 Critical, 26 High, 8 Medium, 2 Low, 0 Unrated.

CVE-2026-38764

Published Jul 23, 2026

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-38766

Published Jul 22, 2026

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-38765

Published Jul 22, 2026

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2019-25764

Published Jul 17, 2026

**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbit…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9492

Published Jul 13, 2026

The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-57851

Published Jul 7, 2026

MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-8797

Published Jun 26, 2026

An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56129

Published Jun 25, 2026

Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administra…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-15641

Published Jun 17, 2026

Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the cus…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-8501

Published Jun 1, 2026

Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and…

CVSS 7.8 · High
evidence mentions
4
Buzz score
31.1

CVE-2026-6737

Published May 8, 2026

An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad informatio…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-36355

Published May 5, 2026

The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks on the write_mem (ioctl 0x89F5…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-4483

Published Apr 8, 2026

An exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxG…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-47761

Published Nov 18, 2025

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-8061

Published Sep 11, 2025

A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow…

CVSS 7.3 · High

CVE-2025-7771

Published Aug 6, 2025

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure impl…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2023-44976

Published Aug 1, 2025

Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E01…

CVSS 3.2 · Low

CVE-2025-26125

Published Mar 17, 2025

An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

CVSS 7.3 · High

CVE-2024-0141

Published Mar 5, 2025

NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to write to an unsupported registry causing a b…

CVSS 6.8 · Medium

CVE-2024-39251

Published Jul 1, 2024

An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, o…

CVSS 10.0 · Critical

CVE-2024-4196

Published Jun 25, 2024

An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Cont…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-33222

Published May 22, 2024

An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execute arbitrary code via sending crafted I…

CVSS 8.4 · High

CVE-2024-33221

Published May 22, 2024

An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending cra…

CVSS 7.8 · High

CVE-2024-33220

Published May 22, 2024

An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOC…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2