Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

514 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.8%—OpenslpDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+3423/4/201817/6/2026
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
ModificadaAlta (7.5)1.1%—Lenovo Help19/4/201817/6/2026
Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information.
ModificadaCrítica (9.8)1.3%—Lenovo Integrated Management Module 219/4/201817/6/2026
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion…
ModificadaAlta (7.8)0.40%—Lenovo Fingerprint Manager PRO26/1/201817/6/2026
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is…
ModificadaAlta (7)0.27%—Lenovo Enterprise Network Operating System10/1/201817/6/2026
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local…
ModificadaMedia (5.3)0.89%—Lenovo Xclarity Administrator30/11/201717/6/2026
A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.
ModificadaAlta (7.5)0.82%—Lenovo Thinkcentre M710s FirmwareLenovo Thinkcentre M710t FirmwareLenovo AIO E95 Firmware26/10/201717/6/2026
System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.
ModificadaCrítica (9.8)4.2%—Lenovo Service Framework17/10/201717/6/2026
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.
ModificadaAlta (8.1)0.78%—Lenovo Service Framework17/10/201717/6/2026
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
ModificadaAlta (8.1)1.7%—Lenovo Service Framework17/10/201717/6/2026
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
ModificadaCrítica (9.8)2.7%—Lenovo Service Framework17/10/201717/6/2026
Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.
ModificadaAlta (7.8)0.47%—Lenovo System Update3/10/201717/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.
ModificadaMedia (6.7)0.34%—Lenovo Fingerprint Manager3/10/201717/6/2026
Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations.
ModificadaAlta (8.8)1.0%—Lenovo Xclarity Administrator22/9/201717/6/2026
Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.
ModificadaMedia (6.7)0.32%—Lenovo Xclarity Administrator22/9/201717/6/2026
An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2.
ModificadaAlta (7.8)0.38%—Lenovo Thinkpad USB 3.0 Ethernet Adapter Driver29/8/201717/6/2026
ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that could allow a local user to execute arbitrary code with administrative or system level privileges.
ModificadaAlta (7.8)0.38%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+14418/8/201717/6/2026
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
ModificadaMedia (6.8)0.52%—Lenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish FirmwareLenovo Ideacentre 510s-08ish FirmwareLenovo Ideacentre 700 Firmware+10710/8/201717/6/2026
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to…
ModificadaAlta (7.8)0.37%—Lenovo Thinkpad Compact USB Keyboard Driver10/8/201717/6/2026
An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges.
ModificadaAlta (8.2)0.44%—IBM 1G L2-7 SLBIBM 1\IBM Layer 2/3 Copper FirmwareIBM Virtual Fabric 10gb+219/8/201717/6/2026
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other…
ModificadaMedia (6.7)0.34%—Lenovo Bios17/7/201717/6/2026
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.
ModificadaMedia (4.8)0.53%—Lenovo Connect217/7/201717/6/2026
In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker with read access to the user's contents…
ModificadaMedia (5.5)0.29%—Lenovo Nerve Center29/6/201717/6/2026
Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.
ModificadaAlta (7.8)0.40%—Lenovo Xclarity Administrator20/6/201717/6/2026
In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative…
ModificadaMedia (6.5)0.84%—Lenovo Integrated Management Module FirmwareIBM Integrated Management Module Firmware20/6/201717/6/2026
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users…