Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.7
CVE-2020-8323
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models…
330 14ast Firmware
Mitigation only
HIGH 7.3
CVE-2019-6196
A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extr…
Installation Package
1.2.9.3+
MEDIUM 6.5
CVE-2019-6173
A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation …
Installation Package
1.2.9.3+
HIGH 7.5
CVE-2020-8329
A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a rem…
Lj4010dn Firmware
1.01+
HIGH 7.5
CVE-2020-8330
A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a rem…
Lj4010dn Firmware
1.01+
HIGH 7.8
CVE-2020-8327
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior…
Vantage
10.2003.10.0+
MEDIUM 5.5
CVE-2020-8324
A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow uns…
System Interface Foundation
1.2.184.31+
HIGH 7.8
CVE-2020-8318
A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could …
System Interface Foundation
2.0.0.92+
HIGH 7.8
CVE-2020-8319
A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated u…
System Interface Foundation
1.1.19.3+
CRITICAL 9.8
CVE-2015-5684
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly…
B50 10 Firmware
Mitigation only
HIGH 8.8
CVE-2015-8536
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2…
Solution Center
3.3.002+
HIGH 7.8
CVE-2015-7333
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed an…
System Update
after 5.07.0008
HIGH 7.8
CVE-2015-7334
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed an…
System Update
after 5.07.0008
HIGH 7.8
CVE-2015-8534
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed …
Solution Center
3.3.002+
HIGH 7.8
CVE-2015-8535
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and pub…
Solution Center
3.3.002+
HIGH 7.5
CVE-2015-7336
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 201…
System Update
after 5.07.0008
HIGH 7.0
CVE-2015-7335
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 20…
System Update
after 5.07.0008
MEDIUM 6.0
CVE-2019-19756
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of manag…
Xclarity Administrator
Mitigation only
HIGH 7.5
CVE-2019-6193
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated…
Xclarity Administrator
2.6.6+
MEDIUM 5.5
CVE-2019-6194
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow i…
Xclarity Administrator
2.6.6+
MEDIUM 5.5
CVE-2019-6190
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and …
Thinkcentre E93 Firmware
Mitigation only
MEDIUM 6.1
CVE-2019-19758
A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated,…
Ez Media \& Backup Center Ix2 Firmware
after 4.1.406.34763
MEDIUM 5.4
CVE-2019-19757
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulner…
Xclarity Administrator
2.6.6+
HIGH 7.5
CVE-2019-6183
A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause s…
Energy Management
15.11.29.7+
HIGH 8.8
CVE-2019-6186
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to exec…
System Interface Foundation
1.1.18.3+
HIGH 7.8
CVE-2019-6184
A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.
Customer Engagement Service
No fix yet
HIGH 7.8
CVE-2019-6189
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to loa…
System Interface Foundation
1.1.18.3+
HIGH 7.8
CVE-2019-6191
A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.
Paper
Mitigation only
HIGH 7.5
CVE-2019-6176
A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.
Thinkpad Usb C Dock Firmware
Patch available
MEDIUM 6.5
CVE-2019-6187
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permi…
Xclarity Controller
Patch available