← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Software Fix
Aug 24, 2026
Apr 15, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
1Lenovo
1Software Fix
Aug 24, 2026
Apr 15, 2026
5.2 MEDIUM· v4
6.6 MEDIUM· v3
N/A· v2
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated pr...Show more
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.Show less
1Lenovo
1Software Fix
Aug 24, 2026
Apr 15, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.
1Lenovo
1Service Bridge
Aug 24, 2026
Apr 15, 2026
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.
1Lenovo
2Diagnostics
Hardware Scan
Aug 24, 2026
Apr 15, 2026
6.9 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a...Show more
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.Show less
1Lenovo
1Pcmanager
Aug 24, 2026
Mar 11, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.
1Lenovo
1Filez
Aug 19, 2026
Mar 11, 2026
7.5 HIGH· v4
7.1 HIGH· v3
N/A· v2
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.
1Lenovo
1Vantage
Jun 17, 2026
Mar 11, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated pri...Show more
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.Show less
1Lenovo
1Vantage
Jun 17, 2026
Mar 11, 2026
6.9 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privil...Show more
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.Show less
1Lenovo
1Vantage
Jun 17, 2026
Mar 11, 2026
6.9 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privil...Show more
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.Show less
1Lenovo
1Smart Connect
Aug 20, 2026
Mar 11, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.
1Lenovo
1Smart Connect
Aug 20, 2026
Mar 11, 2026
6.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.
1Lenovo
1Filez
Aug 19, 2026
Mar 11, 2026
6.0 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.
1Lenovo
1Filez
Aug 19, 2026
Mar 11, 2026
2.4 LOW· v4
2.8 LOW· v3
N/A· v2
A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.
1Lenovo
4Thinkplus Fu100 Firmware
Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 more
Jun 17, 2026
Jan 14, 2026
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.
1Lenovo
4Thinkplus Fu100 Firmware
Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 more
Jun 17, 2026
Jan 14, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.
1Lenovo
4Thinkplus Fu100 Firmware
Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 more
Jun 17, 2026
Jan 14, 2026
5.1 MEDIUM· v4
4.6 MEDIUM· v3
N/A· v2
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.
1Lenovo
1App Store
Jun 17, 2026
Nov 12, 2025
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.
1Lenovo
1Pcmanager
Jun 17, 2026
Oct 15, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.
1Lenovo
1Pcmanager
Jun 17, 2026
Oct 15, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.