← Back

Lenovo

lenovo

395 CVEs • 4,474 products

Products (4,474)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (395)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Vantage
Mar 25, 2026
Mar 11, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated pri...Show more
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.Show less
1Lenovo
1Vantage
Mar 25, 2026
Mar 11, 2026
6.9 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privil...Show more
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.Show less
1Lenovo
1Vantage
Mar 25, 2026
Mar 11, 2026
6.9 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privil...Show more
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.Show less
1Lenovo
4Thinkplus Fu100 Firmware
Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 more
Feb 23, 2026
Jan 14, 2026
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.
1Lenovo
4Thinkplus Fu100 Firmware
Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 more
Jun 1, 2026
Jan 14, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.
1Lenovo
4Thinkplus Fu100 Firmware
Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 more
Jun 1, 2026
Jan 14, 2026
5.1 MEDIUM· v4
4.6 MEDIUM· v3
N/A· v2
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.
1Lenovo
1App Store
Feb 2, 2026
Nov 12, 2025
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.
1Lenovo
1Pcmanager
Feb 2, 2026
Oct 15, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.
1Lenovo
1Pcmanager
Feb 2, 2026
Oct 15, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.
1Lenovo
1Pcmanager
Jan 27, 2026
Aug 18, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.
1Lenovo
2Commercial Vantage
Vantage
Jul 22, 2025
Jul 17, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
1Lenovo
2Commercial Vantage
Vantage
Jul 22, 2025
Jul 17, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
1Lenovo
2Commercial Vantage
Vantage
Aug 19, 2025
Jul 17, 2025
4.8 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.
1Lenovo
1Pcmanager
Feb 2, 2026
May 30, 2025
6.9 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.
1Lenovo
1Pcmanager
Feb 2, 2026
May 30, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
1Lenovo
1Pcmanager
Feb 2, 2026
May 30, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
1Lenovo
1Starstudio
Oct 17, 2024
Oct 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.
1Lenovo
1Dolby Vision Provisioning
Nov 15, 2024
Oct 11, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevat...Show more
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by this issue.Show less
1Lenovo
1Lock Screen
Oct 17, 2024
Oct 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.
1Lenovo
1Emulator
Oct 17, 2024
Oct 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.