Lenovo
lenovo
406 CVEs • 4,477 products
Products (4,477)
Click to collapseToggle
Products (4,477)
Click to collapse
CVEs (406)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure. |
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure. |
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure. |
1Lenovo 136Aio300 23isu Firmware Aio310 20iap FirmwareAio510 22ish Firmware+133 moreJun 17, 2026 Dec 26, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles...Show more |
1Lenovo 1Elan Miniport Touchpad Driver Jun 17, 2026 Nov 7, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled...Show more |
A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially crafted website. |
1Lenovo 1Smart Standby Driver Jun 17, 2026 May 18, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service. |
1Lenovo 5A1 Firmware T1 FirmwareT2 Firmware+2 moreJun 17, 2026 May 18, 2022 N/A· v4 8.0 HIGH· v3 7.7 HIGH· v2 A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device. |
1Lenovo 5A1 Firmware T1 FirmwareT2 Firmware+2 moreJun 17, 2026 May 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account. |
1Lenovo 5A1 Firmware T1 FirmwareT2 Firmware+2 moreJun 17, 2026 May 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local net...Show more |
1Lenovo 5A1 Firmware T1 FirmwareT2 Firmware+2 moreJun 17, 2026 May 18, 2022 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access. |
1Lenovo 5A1 Firmware T1 FirmwareT2 Firmware+2 moreJun 17, 2026 May 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details. |
1Lenovo 1System Interface Foundation Jun 17, 2026 May 18, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privilege...Show more |
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an L...Show more |
1Lenovo 1System Interface Foundation Jun 17, 2026 May 18, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMCont...Show more |
1Lenovo 1Thinkpad X1 Fold Gen 1 Firmware Jun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute a...Show more |
1Lenovo 30Thinkpad 11e Firmware Thinkpad 11e Yoga FirmwareThinkpad Helix Firmware+27 moreJun 17, 2026 Apr 22, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privil...Show more |
A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash. |
A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update packa...Show more |
A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation. |