Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vantage HIGH 7.1
CVE-2026-1716

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local au…

Fix: 1.0.8.15+
Fix from $1,950 2026-03-11
Filez HIGH 7.1
CVE-2026-2368

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network…

Fix: 10.12.3.0 / 11.1.0.35+
Fix from $1,950 2026-03-11
Vantage MEDIUM 5.5
CVE-2026-1717

An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a loca…

Fix: 1.0.0.138+
Fix from $1,600 2026-03-11
Vantage HIGH 7.1
CVE-2026-1715

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local au…

Fix: 1.0.8.15+
Fix from $1,950 2026-03-11
Filez MEDIUM 5.3
CVE-2026-1068

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network…

Fix: 10.12.3.0 / 11.1.0.35+
Fix from $1,600 2026-03-11
Thinkplus Fu100 Firmware HIGH 7.8
CVE-2025-13455

A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authenticatio…

Mitigation only
Fix from $1,950 2026-01-14
Thinkplus Fu100 Firmware MEDIUM 5.5
CVE-2025-13454

A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive de…

Mitigation only
Fix from $1,600 2026-01-14
App Store HIGH 7.3
CVE-2025-8485

An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated priv…

Fix: 9.0.2530.1027+
Fix from $1,950 2025-11-12
Pcmanager HIGH 7.8
CVE-2025-8486

A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.

Fix: 5.1.140.9262+
Fix from $1,950 2025-10-15
Pcmanager HIGH 7.8
CVE-2025-10581

A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authe…

Fix: 5.1.140.9262+
Fix from $1,950 2025-10-15
Pcmanager HIGH 7.8
CVE-2025-8098

An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.

Fix: 5.1.120.7041+
Fix from $1,950 2025-08-18
Commercial Vantage HIGH 7.8
CVE-2025-6231

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with e…

Fix: 10.2501.20.0 / 20.2506.39.0+
Fix from $1,950 2025-07-17
Commercial Vantage HIGH 7.8
CVE-2025-6232

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with e…

Fix: 10.2501.20.0 / 20.2506.39.0+
Fix from $1,950 2025-07-17
Commercial Vantage MEDIUM 5.3
CVE-2025-6230

A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limite…

Fix: 10.2501.20.0 / 20.2506.39.0+
Fix from $1,600 2025-07-17
Pcmanager HIGH 7.8
CVE-2025-2501

An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

Fix: 5.1.110.5082+
Fix from $1,950 2025-05-30
Pcmanager HIGH 7.8
CVE-2025-2502

An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

Fix: 5.1.110.5082+
Fix from $1,950 2025-05-30
Pcmanager HIGH 7.1
CVE-2025-2503

An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions…

Fix: 5.1.110.5082+
Fix from $1,950 2025-05-30
Starstudio HIGH 7.8
CVE-2024-9046

A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.

Fix: 2020.3.12.34806+
Fix from $1,950 2024-10-11
Emulator HIGH 7.8
CVE-2024-4131

A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.

Fix: 9.1.6+
Fix from $1,950 2024-10-11
Lock Screen HIGH 7.8
CVE-2024-4132

A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.

Fix: 9.0.18+
Fix from $1,950 2024-10-11
Dolby Vision Provisioning MEDIUM 5.5
CVE-2024-5474

A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 th…

Fix: 2.0.0.2+
Fix from $1,600 2024-10-11
Superfile HIGH 7.8
CVE-2024-4089

A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges.

Fix: 2.4+
Fix from $1,950 2024-10-11
App Store HIGH 7.8
CVE-2024-4130

A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.

Fix: 9.0.17+
Fix from $1,950 2024-10-11
Xclarity Administrator MEDIUM 6.5
CVE-2024-45104

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a sp…

Fix: 4.1.0+
Fix from $1,600 2024-09-13
Drivers Management HIGH 7.8
CVE-2023-1577

A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code wit…

Fix: 3.1.1307.1308+
Fix from $1,950 2024-07-31
Pcmanager HIGH 7.8
CVE-2019-6197

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Fix: 2.8.90.11211+
Fix from $1,950 2024-07-31
Pcmanager HIGH 7.8
CVE-2019-6198

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Fix: 2.8.90.11211+
Fix from $1,950 2024-07-31
Pcmanager MEDIUM 5.5
CVE-2017-3772

A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

Fix: 2.6.40.3154+
Fix from $1,600 2024-07-31
Nextscale N1200 Enclosure Firmware HIGH 7.2
CVE-2024-2659

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute syste…

Mitigation only
Fix from $1,950 2024-04-15
Tab M8 Hd Tb8505f Firmware HIGH 7.8
CVE-2023-5080

A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and…

Fix: 8505xs_usr_s301077_2309140036_v9.56_bmp_row / 8505f_usr_s301106_2309140042_v9.56_bmp_row+
Fix from $1,950 2024-01-19