Lenovo
lenovo
406 CVEs • 4,477 products
Products (4,477)
Click to collapseToggle
Products (4,477)
Click to collapse
CVEs (406)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 1Xclarity Administrator May 13, 2026 Mar 1, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user. |
Privilege escalation vulnerability in Lenovo Transition application used in Lenovo Yoga, Flex and Miix systems running Windows allows local users to execute code with elevated privileges. |
1Lenovo 11Flex System X240 M5 Bios Flex System X280 M6 BiosFlex System X480 X6 Bios+8 moreMay 13, 2026 Jan 26, 2017 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure. |
1Lenovo 2Edge Keyboard Driver Slim Usb Keyboard DriverMay 13, 2026 Jan 26, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges. |
Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users ma...Show more |
3Hp IntelLenovo28Converged Hx5500 Appliance Converged Hx5510 ApplianceConverged Hx7500 Appliance+25 moreMay 6, 2026 Jan 9, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain netw...Show more |
1Lenovo 74Thinkpad 10 Ella 2 Bios Thinkpad 11e Beema BiosThinkpad 11e Braswell Bios+71 moreMay 6, 2026 Nov 30, 2016 N/A· v4 4.4 MEDIUM· v3 4.7 MEDIUM· v2 A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. Th...Show more |
1Lenovo 29Bios Notebook 110 14ibr BiosNotebook 110 15ibr Bios+26 moreMay 6, 2026 Nov 29, 2016 N/A· v4 4.4 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) prote...Show more |
1Lenovo 1System Interface Foundation May 6, 2026 Nov 29, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could ru...Show more |
The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation...Show more |
4Amazonbasics DellLenovo+1 more5Firmware Km632 FirmwareKm714 Firmware+2 moreMay 6, 2026 Aug 2, 2016 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which...Show more |
Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors. |
Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via vectors involving the LSC.Services.SystemService StartProxy command with a named pipe created in ad...Show more |
The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument. |
UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com. |
Cross-site scripting (XSS) vulnerability in Lenovo SHAREit before 3.5.98_ww on Android before 4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)." |
Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent scheme URL attack." |
The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows re...Show more |
1Lenovo 2Fingerprint Manager Touch FingerprintMay 6, 2026 Apr 11, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks. |
6Cisco LenovoSamsung+3 more6Gs1900 10hp Firmware Ios XeKeymouse Firmware+3 moreMay 6, 2026 Mar 26, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293. |