Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

514 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.73%—Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer20/6/201717/6/2026
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text…
ModificadaAlta (7.8)0.30%—Lenovo Mouse Suite13/6/201717/6/2026
Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.
ModificadaBaja (3.3)0.26%—Lenovo Power Management4/6/201717/6/2026
In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.
ModificadaMedia (5.5)0.35%—Lenovo Active Protection System4/6/201717/6/2026
In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.
ModificadaAlta (7.5)0.51%—Lenovo Service Bridge4/6/201717/6/2026
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.
ModificadaAlta (7.5)1.1%—Lenovo Service Bridge4/6/201717/6/2026
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.
ModificadaAlta (8.8)0.45%—Lenovo Service Bridge4/6/201717/6/2026
A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.
ModificadaAlta (7.8)0.37%—Lenovo Service Bridge4/6/201717/6/2026
In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.
ModificadaAlta (7.8)0.32%—Lenovo Solution Center23/5/201717/6/2026
The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.
ModificadaAlta (7.8)0.50%—Lenovo System Update24/4/201717/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation…
ModificadaAlta (7)0.37%—Lenovo System Update24/4/201717/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."
ModificadaAlta (8.1)3.3%—Lenovo Updates10/4/201717/6/2026
Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.
ModificadaAlta (7.8)0.42%—Lenovo Customer Care Software Development KIT10/4/201717/6/2026
Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitApache StrutsIBM Storwize V3500 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V7000 Firmware+511/3/201717/6/2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP…
ModificadaAlta (7.5)0.82%—Lenovo Thinkserver Firmware3/3/201717/6/2026
Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions earlier than 3.77.
ModificadaCrítica (9.8)1.1%—Lenovo Xclarity Administrator1/3/201717/6/2026
Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.
ModificadaAlta (7.8)0.35%—Lenovo Transition26/1/201717/6/2026
Privilege escalation vulnerability in Lenovo Transition application used in Lenovo Yoga, Flex and Miix systems running Windows allows local users to execute code with elevated privileges.
ModificadaMedia (4.9)0.92%—Lenovo Flex System X240 M5 BiosLenovo Flex System X280 M6 BiosLenovo Flex System X480 X6 BiosLenovo Flex System X880 X6 Bios+726/1/201717/6/2026
The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure.
ModificadaAlta (7.8)0.35%—Lenovo Edge Keyboard DriverLenovo Slim USB Keyboard Driver26/1/201717/6/2026
Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges.
ModificadaAlta (7)0.30%—Lenovo Xclarity Administrator12/1/201717/6/2026
Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords for internal administrative LXCA accounts with temporary passwords that are…
ModificadaMedia (5.9)5.1%—Intel Ethernet Controller X710 FirmwareIntel Ethernet Controller Xl710 FirmwareHP Ethernet 10gb 2-port 562flr-sfp+HP Ethernet 10gb 2-port 562sfp++249/1/201717/6/2026
A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.
ModificadaMedia (4.4)0.30%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+7030/11/201617/6/2026
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be…
ModificadaMedia (4.4)0.30%—Lenovo BiosLenovo Notebook 110 14ibr BiosLenovo Notebook 110 15ibr BiosLenovo Notebook B70 80 Bios+2529/11/201617/6/2026
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
ModificadaAlta (7.8)0.31%—Lenovo System Interface Foundation29/11/201617/6/2026
During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges.
ModificadaAlta (7.8)0.38%—Lenovo Bios22/9/201617/6/2026
The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might allow local users or physically proximate attackers to bypass…