← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Smart Clock Essential With Alexa Built In Firmware
Jun 17, 2026
May 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access.
1Lenovo
109Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 more
Jun 17, 2026
Apr 28, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have t...Show more
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.Show less
1Lenovo
1Drivers Management
Jun 17, 2026
Apr 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges.
1Lenovo
109Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 more
Jun 17, 2026
Apr 28, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposu...Show more
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configuredShow less
1Lenovo
109Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 more
Jun 17, 2026
Apr 28, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no...Show more
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.Show less
1Lenovo
109Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 more
Jun 17, 2026
Apr 28, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentica...Show more
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.Show less
1Lenovo
287Ideacentre 3 07ada05 Firmware
Ideacentre 3 07imb05 FirmwareIdeacentre 3 07iab7 Firmware+284 more
Jun 17, 2026
Jan 30, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1Lenovo
147Ideacentre 3 07ada05 Firmware
Ideacentre 3 07imb05 FirmwareIdeacentre 3 07iab7 Firmware+144 more
Jun 17, 2026
Jan 30, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
1Lenovo
136Ideacentre 3 07ada05 Firmware
Ideacentre 3 07imb05 FirmwareIdeacentre 3 07iab7 Firmware+133 more
Jun 17, 2026
Jan 30, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
1Lenovo
325Ideacentre 3 07ada05 Firmware
Ideacentre 3 07imb05 FirmwareIdeacentre 3 07iab7 Firmware+322 more
Jun 17, 2026
Jan 30, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
1Lenovo
98Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+95 more
Jun 17, 2026
Jan 30, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, rem...Show more
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.Show less
1Lenovo
98Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+95 more
Jun 17, 2026
Jan 30, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
1Lenovo
1Ideapad Y700 14isk Firmware
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modify...Show more
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.Show less
1Lenovo
70100e 2nd Gen Firmware
100w Gen 3 Firmware13w Yoga Firmware+67 more
Jun 17, 2026
Jan 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
1Lenovo
6Thinkbook 14 Iil Firmware
Thinkbook 14 Iml FirmwareThinkbook 15 Iil Firmware+3 more
Jun 17, 2026
Jan 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
1Lenovo
6Thinkbook 14 Iil Firmware
Thinkbook 14 Iml FirmwareThinkbook 15 Iil Firmware+3 more
Jun 17, 2026
Jan 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
1Lenovo
1Safecenter
Jun 17, 2026
Jan 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.
1Lenovo
44D330 10igl Firmware
Ideapad 5 Pro 16arh7 FirmwareIdeapad 5 Pro 16iah7 Firmware+41 more
Jun 17, 2026
Jan 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
1Lenovo
1Leyun
Jun 17, 2026
Jan 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
1Lenovo
1Thinkpad X13s Firmware
Jun 17, 2026
Jan 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.