Lenovo
lenovo
395 CVEs • 4,474 products
Products (4,474)
Click to collapseToggle
Products (4,474)
Click to collapse
CVEs (395)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 2Thinkpad T14s Gen 3 Firmware Thinkpad X13 Gen 3 FirmwareJun 17, 2026 Oct 9, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
|
1Lenovo 2Thinkpad T14s Gen 3 Firmware Thinkpad X13 Gen 3 FirmwareJun 17, 2026 Oct 9, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
|
1Lenovo 2Thinkpad T14s Gen 3 Firmware Thinkpad X13 Gen 3 FirmwareJun 17, 2026 Oct 9, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
|
1Lenovo 25D330 10igl Firmware Ideapad 5 Pro 16ach6 FirmwareIdeapad 5 Pro 16ihu6 Firmware+22 moreJun 17, 2026 Oct 9, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot se...Show more |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Emb...Show more |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI. |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credentia...Show more |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Control...Show more |
1Lenovo 87Ideapad 1 14ijl7 Firmware Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 moreJun 17, 2026 Aug 23, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. |
1Lenovo 4Thinkpad P14s Gen 2 Firmware Thinkpad P15s Gen 2 FirmwareThinkpad T14 Gen 2 Firmware+1 moreJun 17, 2026 Aug 17, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt. |
1Lenovo 26K14 Type 21cu Firmware K14 Type 21cv FirmwareThinkpad E14 Gen 3 Firmware+23 moreJun 17, 2026 Aug 17, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code. |
1Lenovo 2913w Yoga Firmware 13w Yoga Gen 2 FirmwareFlex 5 14alc05 Firmware+26 moreJun 17, 2026 Aug 17, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. |
An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges. |
1Lenovo 30Legion 5 15ach6 Firmware Legion 5 15ach6a FirmwareLegion 5 15ach6h Firmware+27 moreJun 17, 2026 Aug 17, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. |
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. |
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. |
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. |
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. |
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. |
1Lenovo 8Nextscale N1200 Enclosure Firmware Thinkagile Cp Cb 10 FirmwareThinkagile Cp Cb 10e Firmware+5 moreJun 17, 2026 Jun 26, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normal...Show more |