Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.27%—Lenovo Thinkpad 11E FirmwareLenovo Thinkpad Helix FirmwareLenovo Thinkpad L560 FirmwareLenovo Thinkpad L570 Firmware+2622/4/202217/6/2026
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
ModificadaMedia (6.7)0.28%—Lenovo Thinkpad 11E 3RD GEN FirmwareLenovo Thinkpad 11E 4TH GEN I3 FirmwareLenovo Thinkpad 11E 4TH GEN I7 FirmwareLenovo Thinkpad 11E 4TH GEN I5 Firmware+2512/11/202117/6/2026
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (5.5)0.23%—Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+12912/11/202117/6/2026
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
ModificadaMedia (4.6)0.22%—Lenovo Thinkpad 11E 3RD GEN FirmwareLenovo Thinkpad 11E 4TH GEN I3 FirmwareLenovo Thinkpad 11E 4TH GEN I7 FirmwareLenovo Thinkpad 11E 4TH GEN I5 Firmware+3512/11/202117/6/2026
A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.
ModificadaMedia (6.7)0.29%—Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+12912/11/202117/6/2026
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)0.33%—Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+1689/6/202017/6/2026
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
ModificadaMedia (6.8)0.28%—Lenovo Thinkpad 11E Yoga GEN 6 FirmwareLenovo Thinkpad 11E FirmwareLenovo Thinkpad Yoga 11E 3RD GEN FirmwareLenovo Thinkpad Yoga 11E 4TH GEN Firmware+969/6/202017/6/2026
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
ModificadaCrítica (9.8)1.3%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
ModificadaMedia (6.4)0.33%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.4)0.35%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.5)1.2%—Lenovo Legion Y520t Z370 FirmwareLenovo Aio310-20iap FirmwareLenovo Aio510-22ish FirmwareLenovo Aio510-23ish Firmware+10429/8/201917/6/2026
There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected products and versions: Legion Y520T_Z370 6.0.1.8642, AIO310-20IAP 6.0.1.8642, AIO510-22ISH 6.0.1.8642, AIO510-23ISH…
ModificadaAlta (7.6)0.55%—Intel Core I3Intel Core I5Intel Core I7Intel Core I9+2821/9/201817/6/2026
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware…
ModificadaAlta (7.8)0.38%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+14418/8/201717/6/2026
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
ModificadaMedia (4.4)0.30%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+7030/11/201617/6/2026
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be…