Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

514 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.4)0.21%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+1078/11/202317/6/2026
A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
ModificadaMedia (6.7)0.23%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+1078/11/202317/6/2026
A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)0.18%—Lenovo Thinkpad 25 FirmwareLenovo Thinkpad L560 FirmwareLenovo Thinkpad P50 FirmwareLenovo Thinkpad P50s Firmware+930/10/202317/6/2026
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
ModificadaMedia (6.7)0.19%—Lenovo Thinkpad X13 Yoga GEN 2 FirmwareLenovo Thinkpad X13 Yoga GEN 1 FirmwareLenovo Thinkpad X13 GEN 3 FirmwareLenovo Thinkpad X13 GEN 2 Firmware+5030/10/202317/6/2026
An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)0.19%—Lenovo Thinkpad X1 Fold GEN 1 Firmware30/10/202317/6/2026
An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)0.19%—Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E14 GEN 2 FirmwareLenovo Thinkpad E14 GEN 4 FirmwareLenovo Thinkpad E15 Firmware+8130/10/202317/6/2026
An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaAlta (7.1)0.12%—Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin27/10/202317/6/2026
A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions.
ModificadaAlta (7.8)0.12%—Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin27/10/202317/6/2026
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.
ModificadaMedia (6.3)0.10%—Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin27/10/202317/6/2026
A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files.
ModificadaAlta (7.5)0.41%—Lenovo APP Store APP27/10/202317/6/2026
An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to sensitive user data used by other unrelated applications.
ModificadaMedia (6.5)0.49%—Lenovo Gm265dn FirmwareLenovo Gm266dns FirmwareLenovo G263dns Firmware27/10/202317/6/2026
A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.
ModificadaMedia (5.4)0.27%—Lenovo Gm265dn FirmwareLenovo Gm266dns FirmwareLenovo G263dns Firmware27/10/202317/6/2026
Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.
ModificadaAlta (8.8)0.89%—Lenovo Gm265dn FirmwareLenovo Gm266dns FirmwareLenovo G263dns Firmware27/10/202317/6/2026
A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.
ModificadaAlta (7.2)0.40%—Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+5425/10/202317/6/2026
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
ModificadaAlta (8.8)0.52%—Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+11925/10/202317/6/2026
An authenticated XCC user can change permissions for any user through a crafted API command.
ModificadaAlta (8.1)0.55%—Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+5425/10/202317/6/2026
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
ModificadaAlta (7.8)4.2%💥 ExploitLenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin25/10/202317/6/2026
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.
ModificadaMedia (4.4)0.21%—Lenovo DiagnosticsLenovo Hardwarescan Plugin25/10/202317/6/2026
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
ModificadaMedia (4.4)0.21%—Lenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin25/10/202317/6/2026
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
ModificadaMedia (6.8)0.26%—Lenovo Thinkpad T14s GEN 3 FirmwareLenovo Thinkpad X13 GEN 3 Firmware9/10/202317/6/2026
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
ModificadaMedia (6.8)0.26%—Lenovo Thinkpad T14s GEN 3 FirmwareLenovo Thinkpad X13 GEN 3 Firmware9/10/202317/6/2026
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
ModificadaMedia (6.8)0.26%—Lenovo Thinkpad T14s GEN 3 FirmwareLenovo Thinkpad X13 GEN 3 Firmware9/10/202317/6/2026
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
ModificadaAlta (7.8)0.21%—Lenovo Ideapad Creator 5-16ach6 FirmwareLenovo Ideapad 5 Pro-16ihu6 FirmwareLenovo Ideapad 5 Pro-16ach6 FirmwareLenovo Yoga Slim 7-13itl05 Firmware+219/10/202317/6/2026
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
ModificadaMedia (6.7)0.17%—Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+8323/8/202317/6/2026
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.
ModificadaMedia (4.4)0.18%—Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+8323/8/202317/6/2026
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI.