CVE-2021-41839
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that
CVSS
8.2
High
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Feb 3, 2022 · Last modified: Aug 11, 2026 · CWE-119
0.3%EPSS · 30 days0.3%
2026-08-072026-09-03
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20220217-0016/
- www.insyde.comhttps://www.insyde.com/security-pledge
- www.insyde.comhttps://www.insyde.com/security-pledge/SA-2022020
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20220217-0016/
- www.insyde.comhttps://www.insyde.com/security-pledge
- www.insyde.comhttps://www.insyde.com/security-pledge/SA-2022020
- www.kb.cert.orghttps://www.kb.cert.org/vuls/id/796611
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/html/ssa-306654.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-855225.3 MED—
———A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argument job_name results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 9.0.5 and 9.1.1 addresses this issue. The patch is identified as f4dc3ca09eb650c2fe14060090a41c524eca803f. Upgrading the affected component is advised.19hCVE-2026-851108.8 HIG—
——0A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.2dCVE-2026-851099.8 CRI—
——0A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.2dCVE-2026-850319.9 CRI45.4%
——14A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.2dCVE-2026-767575.9 MED9.7%
——3Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.3dCVE-2026-767565.9 MED9.7%
——3Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.3d