← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Thinkpad X13s Firmware
Jun 17, 2026
Jan 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.
1Lenovo
1Thinkpad X13s Firmware
Jun 17, 2026
Jan 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
1Lenovo
1Thinkpad X13s Firmware
Jun 17, 2026
Jan 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
1Lenovo
136Aio300 23isu Firmware
Aio310 20iap FirmwareAio510 22ish Firmware+133 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles...Show more
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.Show less
1Lenovo
1Elan Miniport Touchpad Driver
Jun 17, 2026
Nov 7, 2022
N/A· v4
4.7 MEDIUM· v3
N/A· v2
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled...Show more
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.Show less
1Lenovo
1Pcmanager
Jun 17, 2026
Aug 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially crafted website.
1Lenovo
1Smart Standby Driver
Jun 17, 2026
May 18, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service.
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Jun 17, 2026
May 18, 2022
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Jun 17, 2026
May 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Jun 17, 2026
May 18, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local net...Show more
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.Show less
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Jun 17, 2026
May 18, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Jun 17, 2026
May 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
1Lenovo
1System Interface Foundation
Jun 17, 2026
May 18, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privilege...Show more
A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privileges.Show less
1Lenovo
1Xclarity Controller
Jun 17, 2026
May 18, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an L...Show more
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.Show less
1Lenovo
1System Interface Foundation
Jun 17, 2026
May 18, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMCont...Show more
A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMController child process' named pipe.Show less
1Lenovo
1Thinkpad X1 Fold Gen 1 Firmware
Jun 17, 2026
Apr 22, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute a...Show more
A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.Show less
1Lenovo
30Thinkpad 11e Firmware
Thinkpad 11e Yoga FirmwareThinkpad Helix Firmware+27 more
Jun 17, 2026
Apr 22, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privil...Show more
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.Show less
1Lenovo
1Thin Installer
Jun 17, 2026
Apr 22, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.
1Lenovo
1System Update
Jun 17, 2026
Apr 22, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update packa...Show more
A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that displays a command prompt window.Show less
1Lenovo
1Pcmanager
Jun 17, 2026
Apr 22, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.