Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

514 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.6)0.60%—Lenovo Personal Cloud StorageAI13/5/202617/6/2026
A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.
Pendiente de análisisAlta (8.7)0.84%—Lenovo Personal Cloud StorageAI13/5/202617/6/2026
A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.
AplazadaMedia (6.4)0.26%—Lenovo VantageAI16/4/202617/6/2026
The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions up to, and including, 1.20.32 due to insufficient output escaping in the gallery template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject…
AnalizadaAlta (8.5)0.21%—Lenovo Software FIX15/4/202624/8/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
AnalizadaMedia (5.2)0.15%—Lenovo Software FIX15/4/202624/8/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
AnalizadaAlta (7)0.17%—Lenovo Software FIX15/4/202624/8/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.
AnalizadaMedia (5.4)0.13%—Lenovo Service Bridge15/4/202624/8/2026
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.
AnalizadaMedia (6.9)0.21%💥 PoCLenovo DiagnosticsLenovo Hardware Scan15/4/202624/8/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
AnalizadaMedia (6.8)0.12%—Lenovo Pcmanager11/3/202624/8/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.
AnalizadaAlta (7.5)0.13%—Lenovo Filez11/3/202619/8/2026
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.
AnalizadaMedia (6.8)0.14%—Lenovo Vantage11/3/202617/6/2026
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.
AnalizadaMedia (6.9)0.15%—Lenovo Vantage11/3/202617/6/2026
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.
AnalizadaMedia (6.9)0.15%—Lenovo Vantage11/3/202617/6/2026
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
AnalizadaMedia (6.8)0.09%—Lenovo Smart Connect11/3/202620/8/2026
A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.
AnalizadaMedia (6.9)0.09%—Lenovo Smart Connect11/3/202620/8/2026
A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.
AnalizadaMedia (6)0.08%—Lenovo Filez11/3/202619/8/2026
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.
Pendiente de análisisAlta (8.4)0.13%—Lenovo Thinkpad BiosAI11/3/202617/6/2026
A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code.
AnalizadaBaja (2.4)0.09%—Lenovo Filez11/3/202619/8/2026
A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.
AplazadaAlta (7)0.16%—Lenovo Thinkpad L13 GEN 6 BiosAILenovo Thinkpad L13 GEN 6 2in1 BiosAILenovo Thinkpad L14 GEN 6 BiosAILenovo Thinkpad L16 GEN 2 BiosAI14/1/202617/6/2026
A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.
AplazadaBaja (2.4)0.16%—Lenovo TabletsAI14/1/202617/6/2026
A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.
AnalizadaAlta (7.3)0.13%—Lenovo Thinkplus Fu100 FirmwareLenovo Thinkplus Fu200 FirmwareLenovo Thinkplus Tu800 FirmwareLenovo Thinkplus Tsd303 Firmware14/1/202617/6/2026
A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.
AnalizadaMedia (6.8)0.10%—Lenovo Thinkplus Fu100 FirmwareLenovo Thinkplus Fu200 FirmwareLenovo Thinkplus Tu800 FirmwareLenovo Thinkplus Tsd303 Firmware14/1/202617/6/2026
A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.
AnalizadaMedia (5.1)0.14%—Lenovo Thinkplus Fu100 FirmwareLenovo Thinkplus Fu200 FirmwareLenovo Thinkplus Tu800 FirmwareLenovo Thinkplus Tsd303 Firmware14/1/202617/6/2026
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.
AplazadaMedia (6.8)0.14%—Lenovo VantageAILenovo SmartperformanceaddinAI14/1/202617/6/2026
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
AplazadaAlta (8.5)0.12%—Lenovo Baiying ClientAI10/12/202517/6/2026
An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.