Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2706▼ 533 respecto a la semana anterior
Críticas / altas1274▼ 219 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 249 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.17% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential. | |
| Modificada | Media (4.4) | 0.18% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo Thinkpad T15 GEN 2 FirmwareLenovo Thinkpad P14s GEN 2 FirmwareLenovo Thinkpad P15s GEN 2 FirmwareLenovo Thinkpad T14 GEN 2 Firmware | 17/8/2023 | 17/6/2026 | A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo K14 Type 21cu FirmwareLenovo K14 Type 21cv FirmwareLenovo Thinkpad S2 Yoga GEN 8 FirmwareLenovo Thinkpad E14 GEN 3 Firmware+22 | 17/8/2023 | 17/6/2026 | A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo 13W Yoga FirmwareLenovo 13W Yoga GEN 2 FirmwareLenovo Ideapad 1-11ada05 FirmwareLenovo Ideapad 1-11igl05 Firmware+25 | 17/8/2023 | 17/6/2026 | A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.22% | — | Lenovo Universal Device Client | 17/8/2023 | 17/6/2026 | An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Legion 5 PRO 16iah7h FirmwareLenovo Legion 5 PRO 16iah7 FirmwareLenovo Legion 5 PRO 16arh7 FirmwareLenovo Legion 5 PRO 16arh7h Firmware+26 | 17/8/2023 | 17/6/2026 | A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (7.5) | 0.50% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Alta (7.2) | 1.3% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. | |
| Modificada | Alta (8.1) | 0.55% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. | |
| Modificada | Media (6.3) | 0.29% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Certified Node Firmware+4 | 26/6/2023 | 17/6/2026 | A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute. | |
| Modificada | Alta (7.5) | 0.62% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Certified Node Firmware+4 | 26/6/2023 | 17/6/2026 | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server. | |
| Modificada | Media (6.7) | 0.16% | — | Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E14 GEN 2 FirmwareLenovo Thinkpad E14 GEN 4 FirmwareLenovo Thinkpad E15 Firmware+81 | 26/6/2023 | 17/6/2026 | A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo Ideacentre AIO 3 21itl7 FirmwareLenovo Ideacentre AIO 3-22itl6 FirmwareLenovo Ideacentre AIO 3-24itl6 FirmwareLenovo Ideacentre AIO 3-27itl6 Firmware+23 | 5/6/2023 | 17/6/2026 | A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3 07ach7 FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07ada05 Firmware+110 | 5/6/2023 | 17/6/2026 | An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo Thinkpad Hybrid Usb-c With Usb-a Dock Firmware | 5/6/2023 | 17/6/2026 | A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation. | |
| Modificada | Alta (8.8) | 0.51% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API. | |
| Modificada | Alta (8.8) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo System Update | 1/5/2023 | 17/6/2026 | A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges. | |
| Modificada | Alta (7.5) | 0.26% | — | Lenovo Baiying | 1/5/2023 | 17/6/2026 | A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure. | |
| Modificada | Alta (8.8) | 0.40% | — | Lenovo Smart Clock Essential With Alexa Built IN Firmware | 1/5/2023 | 17/6/2026 | A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access. | |
| Modificada | Media (5.9) | 0.45% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined. |