Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
514 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Lenovo Health Android ApplicationAI | 10/9/2026 | 11/9/2026 | A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information. | |
| Aplazada | Alta (8.5) | 0.19% | — | Lenovo Software FIXAI | 10/9/2026 | 15/9/2026 | An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges. | |
| Aplazada | Alta (8.4) | 0.10% | — | Lenovo File ManagerAI | 10/9/2026 | 11/9/2026 | A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application. | |
| Aplazada | Alta (8.5) | 0.10% | — | Lenovo Filez ClientAI | 10/9/2026 | 11/9/2026 | A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges. | |
| Pendiente de análisis | Alta (7.3) | 0.18% | — | Lenovo System UpdateAI | 13/8/2026 | 24/8/2026 | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Analizada | Media (6.9) | 0.16% | — | Lenovo Dock Manager | 13/8/2026 | 10/9/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges. | |
| Analizada | Alta (8.5) | 0.15% | — | Lenovo Dock Manager | 13/8/2026 | 10/9/2026 | During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Analizada | Alta (7) | 0.13% | — | Lenovo Dock Manager | 13/8/2026 | 10/9/2026 | During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 13/8/2026 | 24/8/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Pendiente de análisis | Alta (7.3) | 0.16% | — | Lenovo VantageAILenovo Commercial VantageAI | 13/8/2026 | 24/8/2026 | During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges. | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Lenovo VantageAILenovo Commercial VantageAI | 13/8/2026 | 24/8/2026 | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges. | |
| Pendiente de análisis | Alta (8.7) | 0.52% | — | Lenovo Xclarity OrchestratorAI | 4/8/2026 | 24/8/2026 | An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance. | |
| Pendiente de análisis | Alta (7) | 0.11% | — | Lenovo Xclarity OrchestratorAI | 4/8/2026 | 24/8/2026 | An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation… | |
| Pendiente de análisis | Baja (1) | 0.13% | — | Lenovo Xclarity Essentials OnecliAI | 4/8/2026 | 24/8/2026 | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges. | |
| Aplazada | Alta (7.3) | 0.13% | — | Lenovo Legion ZoneAILenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code. | |
| Pendiente de análisis | Media (6.8) | 0.13% | — | Lenovo Smart ConnectAI | 16/7/2026 | 16/7/2026 | During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system. | |
| Pendiente de análisis | Alta (8.8) | 1.2% | — | Lenovo Xclarity Integrator FOR Windows Admin CenterAI | 16/7/2026 | 16/7/2026 | The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands. | |
| Aplazada | Alta (7) | 0.17% | — | Lenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Aplazada | Alta (7) | 0.18% | — | Lenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code. | |
| Pendiente de análisis | Alta (8.4) | 0.14% | — | Fluxink Color Management DriverAILenovo Tcnperipheral64AI | 7/7/2026 | 21/7/2026 | FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Windows 11 25H2 HLK… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 10/6/2026 | 17/6/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Pendiente de análisis | Media (5.1) | 0.29% | — | Lenovo Android ApplicationAI | 10/6/2026 | 17/6/2026 | A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents. | |
| Pendiente de análisis | Alta (7.3) | 0.16% | — | Lenovo Smart ConnectAI | 10/6/2026 | 17/6/2026 | A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Pendiente de análisis | Alta (8.4) | 0.12% | — | Lenovo Thinkpad BiosAI | 10/6/2026 | 30/9/2026 | During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM). | |
| Pendiente de análisis | Alta (8.4) | 0.08% | — | Lenovo Thinkpad Embedded Controller FirmwareAI | 10/6/2026 | 30/9/2026 | During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions. |