Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

514 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.8)0.14%—Lenovo TAB K10AI26/7/202417/6/2026
An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.
AplazadaAlta (7.2)1.0%—Lenovo XCCAI26/7/202417/6/2026
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
AplazadaAlta (7.2)1.0%—Lenovo XCCAI26/7/202417/6/2026
A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via a specially crafted request.
AplazadaAlta (7.5)0.44%—Lenovo Service BridgeAI13/6/202417/6/2026
A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited.
AplazadaAlta (7.5)0.45%—Lenovo PrintersAI16/5/202417/6/2026
A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.
AnalizadaAlta (7.2)1.1%—Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Firmware+6415/4/202417/6/2026
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
AplazadaMedia (6.4)0.24%—Lenovo System Recovery BootloaderAIMicrosoft Windows 7AIMicrosoft Windows 8AI15/4/202417/6/2026
A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute arbitrary code.
AplazadaMedia (6.7)0.33%—Lenovo System Recovery BootloaderAIMicrosoft Windows 7AIMicrosoft Windows 8AI15/4/202417/6/2026
A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to modify the boot manager and escalate privileges.
AplazadaAlta (7.5)0.55%—Lenovo PrintersAI5/4/202417/6/2026
A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted LPD packets.
AplazadaAlta (7.5)0.49%—Lenovo PrintersAI5/4/202417/6/2026
A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.
AplazadaMedia (5.3)0.55%—Lenovo PrintersAI5/4/202417/6/2026
A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.
AplazadaMedia (4.9)0.52%—Lenovo PrintersAI5/4/202417/6/2026
A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.
AplazadaMedia (4.9)0.53%—Lenovo PrinterAI5/4/202417/6/2026
A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.
AplazadaMedia (6.3)0.25%—Lenovo DevicesAISynaptics Fingerprint ReaderAIMicrosoft Windows HelloAI5/4/202417/6/2026
An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.
AplazadaMedia (6.7)0.18%—Lenovo NotebookAI5/4/202417/6/2026
A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables.
AplazadaMedia (6.5)0.46%—Lenovo Xclarity AdministratorAI5/4/202417/6/2026
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
AplazadaMedia (6.7)0.18%—Lenovo BiosAILenovo ThinkstationAILenovo Smart EdgeAI5/4/202417/6/2026
A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables.
AplazadaMedia (6.7)0.18%—Lenovo Bios Update Tool DriverAI5/4/202417/6/2026
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.
ModificadaBaja (2.3)0.16%—Lenovo Thinksystem Sr670 V2 Firmware16/2/202417/6/2026
ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS…
ModificadaMedia (5.5)0.16%—Lenovo APP Store19/1/202417/6/2026
An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial of service.
ModificadaMedia (6.8)0.19%—Lenovo Vantage19/1/202417/6/2026
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute arbitrary code with elevated privileges.
ModificadaAlta (7.8)0.17%—Lenovo Vantage19/1/202417/6/2026
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated privileges.
ModificadaBaja (3.3)0.16%—Lenovo TAB M8 HD Tb8505f FirmwareLenovo TAB M8 HD Tb8505fs FirmwareLenovo TAB M8 HD Tb8505x FirmwareLenovo TAB M8 HD Tb8505xs Firmware19/1/202417/6/2026
An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier.
ModificadaAlta (7.8)0.15%—Lenovo TAB M8 HD Tb8505f FirmwareLenovo TAB M8 HD Tb8505fs FirmwareLenovo TAB M8 HD Tb8505x FirmwareLenovo TAB M8 HD Tb8505xs Firmware+219/1/202417/6/2026
A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands.
ModificadaAlta (7.5)0.53%—Lenovo Browser HDLenovo Browser Mobile3/1/202417/6/2026
A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that could result in the disclosure of sensitive information.