Lenovo
lenovo
395 CVEs • 4,474 products
Products (4,474)
Click to collapseToggle
Products (4,474)
Click to collapse
CVEs (395)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated pri...Show more |
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privil...Show more |
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privil...Show more |
1Lenovo 4Thinkplus Fu100 Firmware Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 moreFeb 23, 2026 Jan 14, 2026 7.3 HIGH· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint. |
1Lenovo 4Thinkplus Fu100 Firmware Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 moreJun 1, 2026 Jan 14, 2026 6.8 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information. |
1Lenovo 4Thinkplus Fu100 Firmware Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 moreJun 1, 2026 Jan 14, 2026 5.1 MEDIUM· v4 4.6 MEDIUM· v3 N/A· v2 A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive. |
An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application. |
A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges. |
A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges. |
An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges. |
1Lenovo 2Commercial Vantage VantageJul 22, 2025 Jul 17, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations. |
1Lenovo 2Commercial Vantage VantageJul 22, 2025 Jul 17, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file. |
1Lenovo 2Commercial Vantage VantageAug 19, 2025 Jul 17, 2025 4.8 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands. |
An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user. |
An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges. |
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges. |
A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges. |
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevat...Show more |
A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges. |
A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges. |