← Back

Lenovo

lenovo

406 CVEs • 4,477 products

Products (4,477)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Cisco
LenovoNetgear+4 more
7Gs1900 10hp Firmware
Ios XeJr6150 Firmware+4 more
May 6, 2026
Mar 26, 2016
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
1Lenovo
1Shareit
May 6, 2026
Jan 26, 2016
N/A· v4
6.1 MEDIUM· v3
2.9 LOW· v2
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within...Show more
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.Show less
1Lenovo
1Shareit
May 6, 2026
Jan 26, 2016
N/A· v4
8.8 HIGH· v3
5.4 MEDIUM· v2
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position wi...Show more
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.Show less
1Lenovo
1Shareit
May 6, 2026
Jan 26, 2016
N/A· v4
4.1 MEDIUM· v3
2.7 LOW· v2
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a crafted file request to /list.
1Lenovo
1Shareit
May 6, 2026
Jan 26, 2016
N/A· v4
8.0 HIGH· v3
4.3 MEDIUM· v2
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-i...Show more
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.Show less
2Ibm
Lenovo
2Switch Center
System Networking Switch Center
May 6, 2026
Nov 12, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and...Show more
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.Show less
2Ibm
Lenovo
2Switch Center
System Networking Switch Center
May 6, 2026
Nov 12, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 4099...Show more
The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password.Show less
2Ibm
Lenovo
2Switch Center
System Networking Switch Center
May 6, 2026
Nov 12, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using t...Show more
The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.Show less
2Ibm
Lenovo
2Switch Center
System Networking Switch Center
May 6, 2026
Nov 12, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and...Show more
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read arbitrary text files, via a request to port 40080 or 40443.Show less
6Arista
DebianLenovo+3 more
19Debian Linux
Emc Px12 400r IvxEmc Px12 450r Ivx+16 more
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host O...Show more
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.Show less
1Lenovo
1System Update
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an u...Show more
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.Show less
1Lenovo
1System Update
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
8.3 HIGH· v2
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files...Show more
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.Show less
1Lenovo
1System Update
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update servi...Show more
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.Show less
1Lenovo
1Thinkserver System Manager Baseboard Management Controller Firmware
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM...Show more
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.Show less
1Lenovo
1Thinkserver System Manager Baseboard Management Controller Firmware
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface cr...Show more
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.Show less
1Lenovo
10Thinkserver Rd350
Thinkserver Rd350 FirmwareThinkserver Rd450+7 more
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified v...Show more
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.Show less
1Lenovo
1Usb Enhanced Performance Keyboard
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
2Google
Lenovo
2Android
Shareit
Apr 29, 2026
Mar 3, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by...Show more
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.Show less
1Lenovo
1Thinkpad Bluetooth With Enhanced Data Rate Software
Apr 29, 2026
Jan 21, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijack...Show more
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth.Show less
1Lenovo
1Veriface
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.