Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-822

Untrusted Pointer Dereference

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

212
Assigned CVEs
119th
Commonality Rank
7.6
Avg CVSS
2.4%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-822 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 6, 2017
8 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

212 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-21338HIGH
Windows Kernel Elevation of Privilege Vulnerability
Feb 13, 20247.891YESYES
CVE-2024-35250HIGH
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Jun 11, 20247.885YESYES
CVE-2023-29360HIGH
Microsoft Streaming Service Elevation of Privilege Vulnerability
Jun 14, 20238.475YESNO
CVE-2025-24990HIGH
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming r
Oct 14, 20257.872YESNO
CVE-2023-21768HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Jan 10, 20237.872NOYES
CVE-2023-36033HIGH
Windows DWM Core Library Elevation of Privilege Vulnerability
Nov 14, 20237.870YESNO
CVE-2026-40369HIGH
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
May 12, 20267.843NONO
CVE-2026-58596HIGH
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Jul 12, 20268.339NONO
CVE-2026-48137CRITICAL
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentiall
Jun 19, 20269.839NONO
CVE-2026-50382HIGH
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
Jul 14, 20268.837NONO
View all 212 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
9%
19%
5.0-5.9
16%
6.0-6.9
66%
26%
7.0-7.9
13%
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
5 CVEs
2.4% of CVEs· 95th percentile
Metasploit
2 CVEs
0.9% of CVEs· 87th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
0.9% of CVEs· 80th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products