Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 0.71% | — | Lenovo Thinkserver Rd650 FirmwareLenovo Thinkserver Rd650Lenovo Thinkserver Td350 FirmwareLenovo Thinkserver Td350+6 | 16/4/2015 | 17/6/2026 | Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.32% | — | Lenovo USB Enhanced Performance Keyboard | 16/4/2015 | 17/6/2026 | Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output. | |
| Modificada | Alta (7.5) | 1.1% | — | Google AndroidLenovo Shareit | 3/3/2014 | 17/6/2026 | java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels. | |
| Modificada | Alta (9.3) | 6.4% | — | Lenovo Thinkpad Bluetooth With Enhanced Data Rate Software | 21/1/2014 | 16/6/2026 | Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed… | |
| Modificada | Media (5) | 52% | 💥 Exploit | Landesk Lenovo Thinkmanagement Console | 18/2/2012 | 16/6/2026 | Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request. | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Landesk Lenovo Thinkmanagement Console | 18/2/2012 | 16/6/2026 | Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a… | |
| Modificada | Media (6.9) | 0.40% | — | Lenovo Veriface | 20/2/2009 | 16/6/2026 | Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user. | |
| Modificada | Alta (7.2) | 0.53% | — | Lenovo Resuce AND Recovery | 15/10/2008 | 16/6/2026 | Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name. | |
| Modificada | Baja (2.1) | 0.32% | — | IBM Lenovo 7cetb5ww | 3/9/2008 | 16/6/2026 | IBM Lenovo firmware 7CETB5WW 2.05 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer. | |
| Modificada | Media (5.1) | 1.3% | — | Lenovo Thinkvantage System Update | 21/7/2008 | 16/6/2026 | The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM. | |
| Modificada | Media (5.8) | 2.6% | — | Lenovo Access SupportLenovo Automated Solutions | 15/8/2007 | 16/6/2026 | The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system… | |
| Modificada | Media (5.8) | 2.6% | — | Lenovo Access SupportLenovo Automated Solutions | 15/8/2007 | 16/6/2026 | The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a… | |
| Modificada | Media (5.8) | 4.6% | — | Lenovo Access SupportLenovo Automated Solutions | 15/8/2007 | 16/6/2026 | Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), allows remote attackers to execute arbitrary code via format string specifiers in unknown data. | |
| Modificada | Alta (10) | 1.6% | — | Intel PRO 1000 LAN AdapterLenovo Thinkpad | 7/3/2007 | 16/6/2026 | Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors. |