Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.21% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.18% | — | Lenovo Thinkpad 25 FirmwareLenovo Thinkpad L560 FirmwareLenovo Thinkpad P50 FirmwareLenovo Thinkpad P50s Firmware+9 | 30/10/2023 | 17/6/2026 | A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Thinkpad X13 Yoga GEN 2 FirmwareLenovo Thinkpad X13 Yoga GEN 1 FirmwareLenovo Thinkpad X13 GEN 3 FirmwareLenovo Thinkpad X13 GEN 2 Firmware+50 | 30/10/2023 | 17/6/2026 | An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Thinkpad X1 Fold GEN 1 Firmware | 30/10/2023 | 17/6/2026 | An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E14 GEN 2 FirmwareLenovo Thinkpad E14 GEN 4 FirmwareLenovo Thinkpad E15 Firmware+81 | 30/10/2023 | 17/6/2026 | An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (7.1) | 0.12% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions. | |
| Modificada | Alta (7.8) | 0.12% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges. | |
| Modificada | Media (6.3) | 0.10% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files. | |
| Modificada | Alta (7.5) | 0.41% | — | Lenovo APP Store APP | 27/10/2023 | 17/6/2026 | An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to sensitive user data used by other unrelated applications. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Gm265dn FirmwareLenovo Gm266dns FirmwareLenovo G263dns Firmware | 27/10/2023 | 17/6/2026 | A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly. | |
| Modificada | Media (5.4) | 0.27% | — | Lenovo Gm265dn FirmwareLenovo Gm266dns FirmwareLenovo G263dns Firmware | 27/10/2023 | 17/6/2026 | Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password. | |
| Modificada | Alta (8.8) | 0.89% | — | Lenovo Gm265dn FirmwareLenovo Gm266dns FirmwareLenovo G263dns Firmware | 27/10/2023 | 17/6/2026 | A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow. | |
| Modificada | Alta (7.2) | 0.40% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+54 | 25/10/2023 | 17/6/2026 | An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | |
| Modificada | Alta (8.8) | 0.52% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+119 | 25/10/2023 | 17/6/2026 | An authenticated XCC user can change permissions for any user through a crafted API command. | |
| Modificada | Alta (8.1) | 0.55% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+54 | 25/10/2023 | 17/6/2026 | An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | |
| Modificada | Alta (7.8) | 4.2% | 💥 Exploit | Lenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin | 25/10/2023 | 17/6/2026 | A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges. | |
| Modificada | Media (4.4) | 0.21% | — | Lenovo DiagnosticsLenovo Hardwarescan Plugin | 25/10/2023 | 17/6/2026 | A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash. | |
| Modificada | Media (4.4) | 0.21% | — | Lenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin | 25/10/2023 | 17/6/2026 | A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash. | |
| Modificada | Media (6.8) | 0.26% | — | Lenovo Thinkpad T14s GEN 3 FirmwareLenovo Thinkpad X13 GEN 3 Firmware | 9/10/2023 | 17/6/2026 | A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. | |
| Modificada | Media (6.8) | 0.26% | — | Lenovo Thinkpad T14s GEN 3 FirmwareLenovo Thinkpad X13 GEN 3 Firmware | 9/10/2023 | 17/6/2026 | A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. | |
| Modificada | Media (6.8) | 0.26% | — | Lenovo Thinkpad T14s GEN 3 FirmwareLenovo Thinkpad X13 GEN 3 Firmware | 9/10/2023 | 17/6/2026 | A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. | |
| Modificada | Alta (7.8) | 0.21% | — | Lenovo Ideapad Creator 5-16ach6 FirmwareLenovo Ideapad 5 Pro-16ihu6 FirmwareLenovo Ideapad 5 Pro-16ach6 FirmwareLenovo Yoga Slim 7-13itl05 Firmware+21 | 9/10/2023 | 17/6/2026 | A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 0.17% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface. | |
| Modificada | Media (4.4) | 0.18% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI. |