Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.8) | 0.14% | — | Lenovo TAB K10AI | 26/7/2024 | 17/6/2026 | An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on. | |
| Aplazada | Alta (7.2) | 1.0% | — | Lenovo XCCAI | 26/7/2024 | 17/6/2026 | A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands. | |
| Aplazada | Alta (7.2) | 1.0% | — | Lenovo XCCAI | 26/7/2024 | 17/6/2026 | A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via a specially crafted request. | |
| Aplazada | Alta (7.5) | 0.44% | — | Lenovo Service BridgeAI | 13/6/2024 | 17/6/2026 | A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited. | |
| Aplazada | Alta (7.5) | 0.45% | — | Lenovo PrintersAI | 16/5/2024 | 17/6/2026 | A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request. | |
| Analizada | Alta (7.2) | 1.1% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Firmware+64 | 15/4/2024 | 17/6/2026 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function. | |
| Aplazada | Media (6.4) | 0.24% | — | Lenovo System Recovery BootloaderAIMicrosoft Windows 7AIMicrosoft Windows 8AI | 15/4/2024 | 17/6/2026 | A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute arbitrary code. | |
| Aplazada | Media (6.7) | 0.33% | — | Lenovo System Recovery BootloaderAIMicrosoft Windows 7AIMicrosoft Windows 8AI | 15/4/2024 | 17/6/2026 | A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to modify the boot manager and escalate privileges. | |
| Aplazada | Alta (7.5) | 0.55% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted LPD packets. | |
| Aplazada | Alta (7.5) | 0.49% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password. | |
| Aplazada | Media (5.3) | 0.55% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication. | |
| Aplazada | Media (4.9) | 0.52% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot. | |
| Aplazada | Media (4.9) | 0.53% | — | Lenovo PrinterAI | 5/4/2024 | 17/6/2026 | A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service. | |
| Aplazada | Media (6.3) | 0.25% | — | Lenovo DevicesAISynaptics Fingerprint ReaderAIMicrosoft Windows HelloAI | 5/4/2024 | 17/6/2026 | An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication. | |
| Aplazada | Media (6.7) | 0.18% | — | Lenovo NotebookAI | 5/4/2024 | 17/6/2026 | A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables. | |
| Aplazada | Media (6.5) | 0.46% | — | Lenovo Xclarity AdministratorAI | 5/4/2024 | 17/6/2026 | A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information. | |
| Aplazada | Media (6.7) | 0.18% | — | Lenovo BiosAILenovo ThinkstationAILenovo Smart EdgeAI | 5/4/2024 | 17/6/2026 | A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables. | |
| Aplazada | Media (6.7) | 0.18% | — | Lenovo Bios Update Tool DriverAI | 5/4/2024 | 17/6/2026 | A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. | |
| Modificada | Baja (2.3) | 0.16% | — | Lenovo Thinksystem Sr670 V2 Firmware | 16/2/2024 | 17/6/2026 | ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS… | |
| Modificada | Media (5.5) | 0.16% | — | Lenovo APP Store | 19/1/2024 | 17/6/2026 | An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial of service. | |
| Modificada | Media (6.8) | 0.19% | — | Lenovo Vantage | 19/1/2024 | 17/6/2026 | A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute arbitrary code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.17% | — | Lenovo Vantage | 19/1/2024 | 17/6/2026 | A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated privileges. | |
| Modificada | Baja (3.3) | 0.16% | — | Lenovo TAB M8 HD Tb8505f FirmwareLenovo TAB M8 HD Tb8505fs FirmwareLenovo TAB M8 HD Tb8505x FirmwareLenovo TAB M8 HD Tb8505xs Firmware | 19/1/2024 | 17/6/2026 | An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier. | |
| Modificada | Alta (7.8) | 0.15% | — | Lenovo TAB M8 HD Tb8505f FirmwareLenovo TAB M8 HD Tb8505fs FirmwareLenovo TAB M8 HD Tb8505x FirmwareLenovo TAB M8 HD Tb8505xs Firmware+2 | 19/1/2024 | 17/6/2026 | A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands. | |
| Modificada | Alta (7.5) | 0.53% | — | Lenovo Browser HDLenovo Browser Mobile | 3/1/2024 | 17/6/2026 | A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that could result in the disclosure of sensitive information. |