1. 戴尔计算机多个BIOS驱动程序提权漏洞,影响数亿设备(CVE-2021-21551)
https://labs.sentinelone.com/cve-2021-21551-hundreds-of-millions-of-dell-computers-at-risk-due-to-multiple-bios-driver-privilege-escalation-flaws/
https://www.dell.com/support/kbdoc/en-uk/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability
2. win32k的UAF漏洞可导致提权(CVE-2021-26900)
https://www.zerodayinitiative.com/blog/2021/5/3/cve-2021-26900-privilege-escalation-via-a-use-after-free-vulnerability-in-win32k
3. TG8防火墙预认证 RCE和密码泄露
https://ssd-disclosure.com/ssd-advisory-tg8-firewall-preauth-rce-and-password-disclosure/
4. 思科RV34X系列vpnTimer提权漏洞的根本原因分析(CVE-2021-1520)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
5. Exim邮件服务器中的多个严重漏洞
https://www.qualys.com/2021/05/04/21nails/21nails.txt
6. Python标准库ipaddress对八进制文字的输入验证会导致SSRF和RFI漏洞(CVE-2021-29921)
https://sick.codes/sick-2021-014/
7. Unity游戏开发中的依赖混淆漏洞
https://blog.includesecurity.com/2021/04/dependency-confusion-vulnerabilities-in-unity-game-development/
8. Wagtail XSS + LocalStorage =帐户劫持(CVE-2021-29434)
https://www.immersivelabs.com/resources/blog/wagtail-xss-localstorage-account-hijack/