Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.26% | — | LenovoAI | 30/7/2025 | 17/6/2026 | The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_security/home | |
| Aplazada | Alta (8.4) | 0.17% | — | Lenovo FilezAI | 17/7/2025 | 17/6/2026 | An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions access to application data. | |
| Aplazada | Alta (7.1) | 0.37% | — | Lenovo BrowserAI | 17/7/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content. | |
| Analizada | Alta (8.5) | 0.20% | — | Lenovo Commercial VantageLenovo Vantage | 17/7/2025 | 17/6/2026 | An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations. | |
| Analizada | Alta (8.5) | 0.20% | — | Lenovo Commercial VantageLenovo Vantage | 17/7/2025 | 17/6/2026 | An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file. | |
| Analizada | Media (4.8) | 0.16% | — | Lenovo Commercial VantageLenovo Vantage | 17/7/2025 | 17/6/2026 | A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands. | |
| Aplazada | Alta (8.4) | 0.18% | — | Lenovo Protection DriverAILenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI | 17/7/2025 | 17/6/2026 | A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code. | |
| Aplazada | Media (5.4) | 0.15% | — | Lenovo Trackpoint Quick MenuAI | 17/7/2025 | 17/6/2026 | A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges. | |
| Analizada | Media (6.9) | 0.13% | — | Lenovo Pcmanager | 30/5/2025 | 17/6/2026 | An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user. | |
| Analizada | Alta (8.5) | 0.20% | 💥 PoC | Lenovo Pcmanager | 30/5/2025 | 17/6/2026 | An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges. | |
| Analizada | Alta (8.5) | 0.18% | — | Lenovo Pcmanager | 30/5/2025 | 17/6/2026 | An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges. | |
| Aplazada | Media (4.8) | 0.16% | — | Lenovo Legion SpaceAI | 30/5/2025 | 17/6/2026 | An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code. | |
| Aplazada | Media (5.1) | 0.14% | — | Lenovo FilezAI | 25/4/2025 | 17/6/2026 | An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user. | |
| Aplazada | Media (5.1) | 0.15% | — | Lenovo FilezAI | 25/4/2025 | 17/6/2026 | An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user. | |
| Aplazada | Alta (8.5) | 0.18% | — | Lenovo VantageAI | 12/2/2025 | 17/6/2026 | An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: | |
| Aplazada | Media (6.8) | 0.20% | — | Lenovo LxcaAILenovo XCCAI | 14/1/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances. | |
| Aplazada | Media (4.7) | 0.13% | — | Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI | 14/1/2025 | 17/6/2026 | A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash. | |
| Aplazada | Media (4.7) | 0.12% | — | Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI | 14/1/2025 | 17/6/2026 | A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash. | |
| Aplazada | Alta (7.6) | 0.30% | — | Lenovo FilezAI | 16/12/2024 | 17/6/2026 | An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading. | |
| Analizada | Alta (7.8) | 0.24% | — | Lenovo Starstudio | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges. | |
| Analizada | Media (5.5) | 0.14% | — | Lenovo Dolby Vision Provisioning | 11/10/2024 | 17/6/2026 | A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by… | |
| Analizada | Alta (7.8) | 0.17% | — | Lenovo Lock Screen | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges. | |
| Analizada | Alta (7.8) | 0.17% | — | Lenovo Emulator | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges. | |
| Analizada | Alta (7.8) | 0.17% | — | Lenovo APP Store | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges. | |
| Analizada | Alta (7.8) | 0.17% | — | Lenovo Superfile | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges. |