Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.18% | — | Lenovo Service FrameworkAI | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privileges. | |
| Aplazada | Alta (7.8) | 0.18% | — | Lenovo PC ManagerAI | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker to execute code with elevated privileges. | |
| Aplazada | Alta (7.8) | 0.18% | — | Lenovo Personal CloudAI | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with elevated privileges. | |
| Aplazada | Alta (7.8) | 0.18% | — | Lenovo BaiyingAI | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges. | |
| Aplazada | Alta (7.8) | 0.19% | — | Lenovo LeyunAI | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges. | |
| Aplazada | Alta (7.2) | 1.1% | — | Lenovo XCCAI | 13/9/2024 | 17/6/2026 | A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads. | |
| Aplazada | Media (4.3) | 0.19% | — | Lenovo XCCAI | 13/9/2024 | 17/6/2026 | IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters. | |
| Aplazada | Media (6.8) | 0.27% | — | Lenovo Thinkpad L390 YogaAILenovo 10W NotebookAI | 13/9/2024 | 17/6/2026 | A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell. | |
| Aplazada | Media (6.7) | 0.21% | — | Lenovo ThinksystemAILenovo ThinkstationAI | 13/9/2024 | 17/6/2026 | A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code. | |
| Aplazada | Media (6.7) | 0.17% | — | Lenovo ThinksystemAI | 13/9/2024 | 17/6/2026 | An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code. | |
| Analizada | Media (6.5) | 0.20% | — | Lenovo Xclarity Administrator | 13/9/2024 | 17/6/2026 | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call. | |
| Analizada | Media (4.3) | 0.34% | — | Lenovo Xclarity Administrator | 13/9/2024 | 17/6/2026 | A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges. | |
| Aplazada | Media (6.8) | 0.20% | — | Lenovo LxcaAI | 13/9/2024 | 17/6/2026 | A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL. | |
| Aplazada | Media (6.7) | 0.17% | — | Lenovo NotebookAI | 13/9/2024 | 17/6/2026 | A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code. | |
| Aplazada | Media (6.5) | 0.26% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted. | |
| Aplazada | Media (6.5) | 0.26% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being reachable until the system is rebooted. | |
| Aplazada | Media (6.5) | 0.26% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the system is rebooted. | |
| Aplazada | Media (6.5) | 0.30% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until a manual system reboot occurs. | |
| Aplazada | Media (6.5) | 0.34% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the system is rebooted. | |
| Aplazada | Alta (7.8) | 0.16% | — | Lenovo Display Control CenterAILenovo Accessories AND Display ManagerAI | 16/8/2024 | 17/6/2026 | An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel. | |
| Aplazada | Alta (7.8) | 0.16% | — | Lenovo Display Control CenterAILenovo Accessories AND Display ManagerAI | 16/8/2024 | 17/6/2026 | An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges. | |
| Analizada | Alta (7.8) | 0.17% | — | Lenovo Drivers Management | 31/7/2024 | 17/6/2026 | A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated privileges. | |
| Analizada | Alta (7.8) | 0.14% | — | Lenovo Pcmanager | 31/7/2024 | 17/6/2026 | A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges. | |
| Analizada | Alta (7.8) | 0.14% | — | Lenovo Pcmanager | 31/7/2024 | 17/6/2026 | A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges. | |
| Analizada | Media (5.5) | 0.15% | — | Lenovo Pcmanager | 31/7/2024 | 17/6/2026 | A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot. |