Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | HP Simplivity 380 Gen9 FirmwareHP Simplivity 380 Gen10 G FirmwareHP Simplivity 380 Gen10 FirmwareHP Simplivity 2600 Gen10 Firmware+4 | 3/1/2020 | 17/6/2026 | A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. Two now deprecated APIs run as… | |
| Modificada | Media (4.4) | 1.7% | 💥 Exploit | Lenovo Power Management Driver | 10/12/2019 | 17/6/2026 | A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service. | |
| Modificada | Alta (7.5) | 1.9% | — | Lenovo Energy Management | 10/12/2019 | 17/6/2026 | A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a client utility. Lenovo XClarity Energy Manager is not affected. | |
| Modificada | Alta (7.8) | 0.32% | — | Lenovo Paper | 20/11/2019 | 17/6/2026 | A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation. | |
| Modificada | Alta (7.8) | 0.32% | — | Lenovo System Interface Foundation | 20/11/2019 | 17/6/2026 | A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL. | |
| Modificada | Media (6.5) | 0.86% | — | Lenovo Xclarity Controller | 20/11/2019 | 17/6/2026 | A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted… | |
| Modificada | Alta (8.8) | 1.5% | — | Lenovo System Interface Foundation | 20/11/2019 | 17/6/2026 | A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user. | |
| Modificada | Alta (7.8) | 0.39% | — | Lenovo Customer Engagement Service | 20/11/2019 | 17/6/2026 | A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation. | |
| Modificada | Alta (7.5) | 1.0% | — | Lenovo Thinkpad Usb-c Dock Firmware | 20/11/2019 | 17/6/2026 | A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access. | |
| Modificada | Media (6.4) | 0.33% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Media (6.4) | 0.35% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Alta (7.5) | 1.7% | — | Lenovo System Update | 26/9/2019 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations. | |
| Modificada | Alta (7.5) | 1.4% | — | Lenovo CP Storage Block Firmware | 26/9/2019 | 17/6/2026 | An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to be reused, which could provide unauthorized access to the BMC under certain circumstances. This… | |
| Modificada | Media (4.9) | 0.65% | — | Lenovo Xclarity Administrator | 3/9/2019 | 17/6/2026 | A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on… | |
| Modificada | Media (6.1) | 0.82% | — | Lenovo Xclarity Administrator | 3/9/2019 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the user's web browser. The JavaScript code is not executed on LXCA itself. | |
| Modificada | Media (4.8) | 0.65% | — | Lenovo Xclarity Administrator | 3/9/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the user's web browser. The JavaScript code is not executed on LXCA itself. | |
| Modificada | Alta (7.5) | 1.4% | — | Lenovo Xclarity AdministratorLenovo Xclarity Integrator | 3/9/2019 | 17/6/2026 | An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow… | |
| Modificada | Media (6.5) | 1.2% | — | Lenovo Legion Y520t Z370 FirmwareLenovo Aio310-20iap FirmwareLenovo Aio510-22ish FirmwareLenovo Aio510-23ish Firmware+104 | 29/8/2019 | 17/6/2026 | There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected products and versions: Legion Y520T_Z370 6.0.1.8642, AIO310-20IAP 6.0.1.8642, AIO510-22ISH 6.0.1.8642, AIO510-23ISH… | |
| Modificada | Crítica (9.8) | 1.1% | — | Lenovo Solution Center | 21/8/2019 | 17/6/2026 | A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Lenovo Vantage or… | |
| Modificada | Media (5.3) | 1.1% | — | Lenovo Px12-350r FirmwareLenovo Ix12-300r FirmwareLenovo Home Media Network Hard Drive FirmwareLenovo Storecenter Ix2-200 Firmware+2 | 19/8/2019 | 17/6/2026 | An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents. | |
| Modificada | Media (6.8) | 0.34% | — | Lenovo 20f1 FirmwareLenovo 20f2 FirmwareLenovo 20jq FirmwareLenovo 20jr Firmware+144 | 19/8/2019 | 17/6/2026 | A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware. | |
| Modificada | Alta (7.8) | 0.37% | — | Lenovo Yoga 700-11isk FirmwareLenovo Yoga 700-14isk Firmware | 19/8/2019 | 17/6/2026 | A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Night light feature introduced in Windows 10 Build 1703 provides similar features. | |
| Modificada | Media (6.1) | 1.1% | — | Lenovo Bladecenter Hs22 FirmwareLenovo Bladecenter Hs22v FirmwareLenovo Bladecenter HX5 FirmwareLenovo System X Idataplex Dx360 M2 Firmware+11 | 19/8/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code to be stored in the IMM log which may then be executed in the… | |
| Modificada | Alta (7.5) | 1.4% | — | Lenovo Px12-350r FirmwareLenovo Ix12-300r FirmwareLenovo Home Media Network Hard Drive FirmwareLenovo Storcenter Ix2-200 Firmware+2 | 16/7/2019 | 17/6/2026 | A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API. |