Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.3
CVE-2023-2993
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited numb…
Nextscale N1200 Enclosure Firmware
Mitigation only
HIGH 7.5
CVE-2023-2992
An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted …
Nextscale N1200 Enclosure Firmware
Mitigation only
MEDIUM 6.7
CVE-2023-2290
A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute ar…
Thinkpad E14 Firmware
Mitigation only
HIGH 7.8
CVE-2022-48181
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate…
Ideacentre C5 14imb05 Firmware
Mitigation only
HIGH 7.8
CVE-2022-48188
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local ac…
Ideacentre Aio 3 21itl7 Firmware
Mitigation only
HIGH 7.8
CVE-2022-4569
A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local acces…
Thinkpad Hybrid Usb C With Usb A Dock Firmware
1.0.35_v2+
HIGH 8.8
CVE-2023-0683
A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.
Thinkagile Hx5530 Firmware
2.93_afbt30p / 3.72_tei388s+
HIGH 8.8
CVE-2023-25492
A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format str…
Thinkagile Hx5530 Firmware
2.93_afbt30p / 3.72_tei388s+
HIGH 7.0
CVE-2022-4568
A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.
System Update
5.08.01.0005+
MEDIUM 6.2
CVE-2022-48186
A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure.
Baiying
1.1.4+
HIGH 8.8
CVE-2023-0896
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with l…
Smart Clock Essential With Alexa Built In Firmware
90+
HIGH 7.8
CVE-2023-25496
A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code wi…
Drivers Management
3.1.1307.1308+
MEDIUM 5.9
CVE-2023-29056
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be confi…
Thinkagile Hx5530 Firmware
2.93_afbt30p / 3.72_tei388s+
HIGH 8.8
CVE-2023-29057
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privile…
Thinkagile Hx5530 Firmware
2.93_afbt30p / 3.72_tei388s+
MEDIUM 6.5
CVE-2023-29058
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through …
Thinkagile Hx5530 Firmware
2.93_afbt30p / 3.72_tei388s+
MEDIUM 6.7
CVE-2022-40137
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary c…
Ideacentre C5 14imb05 Firmware
Mitigation only
MEDIUM 6.5
CVE-2022-34884
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem den…
Thinkagile Vx3331 Firmware
1.80_afbt20n / 3.60_tei386m+
MEDIUM 6.7
CVE-2022-3432
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an at…
Ideapad Y700 14isk Firmware
Mitigation only
HIGH 7.8
CVE-2022-1891
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrar…
Thinkbook 14 Iml Firmware
Mitigation only
HIGH 7.8
CVE-2022-1892
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrar…
100e 2nd Gen Firmware
Mitigation only
HIGH 7.8
CVE-2022-1890
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Thinkbook 14 Iml Firmware
Mitigation only
MEDIUM 6.7
CVE-2022-3430
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify s…
D330 10igl Firmware
Mitigation only
MEDIUM 5.5
CVE-2022-4816
A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.
Safecenter
7.2.01.0315+
HIGH 7.5
CVE-2022-1109
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
Leyun
6.8.21.99+
HIGH 7.8
CVE-2019-19705
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0…
Ideacentre 510 15ikl Firmware
6.0.8923.1 / 6.0.8924.1+
HIGH 8.8
CVE-2022-1513
A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially craft…
Pcmanager
5.0.10.4191+
HIGH 8.0
CVE-2021-42852
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operat…
A1 Firmware
5.3.6.t1 / 5.3.6.a1+
HIGH 7.8
CVE-2021-42850
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could all…
A1 Firmware
5.3.6.t1 / 5.3.6.a1+
HIGH 7.0
CVE-2021-3969
A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to…
System Interface Foundation
1.1.20.3+
MEDIUM 6.8
CVE-2021-42849
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to…
A1 Firmware
5.3.6.t1 / 5.3.6.a1+