Skip to main content

CWE archive

CWE-822 CVEs

Programmatic archive

224 CVEs tagged with CWE-8229 Critical, 171 High, 41 Medium, 3 Low, 0 Unrated.

CVE-2026-9771

Published Aug 17, 2026

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust bound…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-12364

Published Aug 14, 2026

The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, a…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-8917

Published Aug 11, 2026

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary me…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45198

Published Aug 7, 2026

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7406

Published Aug 6, 2026

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnera…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-19023

Published Aug 5, 2026

Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15029

Published Jul 15, 2026

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physi…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48340

Published Jul 14, 2026

Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue r…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50441

Published Jul 14, 2026

Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-50367

Published Jul 14, 2026

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-58596

Published Jul 12, 2026

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

CVSS 8.3 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-48137

Published Jun 19, 2026

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potential…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 224 CVEsPage 1 of 9