Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

514 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.26%—LenovoAI30/7/202517/6/2026
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_security/home
AplazadaAlta (8.4)0.17%—Lenovo FilezAI17/7/202517/6/2026
An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions access to application data.
AplazadaAlta (7.1)0.37%—Lenovo BrowserAI17/7/202517/6/2026
A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content.
AnalizadaAlta (8.5)0.20%—Lenovo Commercial VantageLenovo Vantage17/7/202517/6/2026
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
AnalizadaAlta (8.5)0.20%—Lenovo Commercial VantageLenovo Vantage17/7/202517/6/2026
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
AnalizadaMedia (4.8)0.16%—Lenovo Commercial VantageLenovo Vantage17/7/202517/6/2026
A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.
AplazadaAlta (8.4)0.18%—Lenovo Protection DriverAILenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI17/7/202517/6/2026
A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.
AplazadaMedia (5.4)0.15%—Lenovo Trackpoint Quick MenuAI17/7/202517/6/2026
A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges.
AnalizadaMedia (6.9)0.13%—Lenovo Pcmanager30/5/202517/6/2026
An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.
AnalizadaAlta (8.5)0.20%💥 PoCLenovo Pcmanager30/5/202517/6/2026
An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
AnalizadaAlta (8.5)0.18%—Lenovo Pcmanager30/5/202517/6/2026
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
AplazadaMedia (4.8)0.16%—Lenovo Legion SpaceAI30/5/202517/6/2026
An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.
AplazadaMedia (5.1)0.14%—Lenovo FilezAI25/4/202517/6/2026
An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.
AplazadaMedia (5.1)0.15%—Lenovo FilezAI25/4/202517/6/2026
An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.
AplazadaAlta (8.5)0.18%—Lenovo VantageAI12/2/202517/6/2026
An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices:
AplazadaMedia (6.8)0.20%—Lenovo LxcaAILenovo XCCAI14/1/202517/6/2026
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances.
AplazadaMedia (4.7)0.13%—Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI14/1/202517/6/2026
A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
AplazadaMedia (4.7)0.12%—Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI14/1/202517/6/2026
A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
AplazadaAlta (7.6)0.30%—Lenovo FilezAI16/12/202417/6/2026
An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.
AnalizadaAlta (7.8)0.24%—Lenovo Starstudio11/10/202417/6/2026
A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.
AnalizadaMedia (5.5)0.14%—Lenovo Dolby Vision Provisioning11/10/202417/6/2026
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by…
AnalizadaAlta (7.8)0.17%—Lenovo Lock Screen11/10/202417/6/2026
A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.
AnalizadaAlta (7.8)0.17%—Lenovo Emulator11/10/202417/6/2026
A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.
AnalizadaAlta (7.8)0.17%—Lenovo APP Store11/10/202417/6/2026
A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.
AnalizadaAlta (7.8)0.17%—Lenovo Superfile11/10/202417/6/2026
A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges.