Vulnerabilities (CVE)

Filtered by vendor Lenovo Subscribe
Total 417 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-63424 1 Lenovo 1 Dock Manager 2026-09-10 N/A 7.3 HIGH
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.
CVE-2026-63425 1 Lenovo 1 Dock Manager 2026-09-10 N/A 7.8 HIGH
During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.
CVE-2026-63426 1 Lenovo 1 Dock Manager 2026-09-10 N/A 7.1 HIGH
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
CVE-2026-2640 1 Lenovo 1 Pcmanager 2026-08-24 N/A 5.5 MEDIUM
During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.
CVE-2026-4134 1 Lenovo 1 Software Fix 2026-08-24 N/A 7.3 HIGH
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.
CVE-2026-4135 1 Lenovo 1 Software Fix 2026-08-24 N/A 6.6 MEDIUM
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
CVE-2026-1636 1 Lenovo 1 Service Bridge 2026-08-24 N/A 6.7 MEDIUM
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.
CVE-2026-4145 1 Lenovo 1 Software Fix 2026-08-24 N/A 7.8 HIGH
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
CVE-2026-0827 1 Lenovo 2 Diagnostics, Hardware Scan 2026-08-24 N/A 7.1 HIGH
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
CVE-2026-1652 1 Lenovo 1 Smart Connect 2026-08-20 N/A 6.1 MEDIUM
A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.
CVE-2026-1653 1 Lenovo 1 Smart Connect 2026-08-20 N/A 5.5 MEDIUM
A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.
CVE-2026-2368 1 Lenovo 1 Filez 2026-08-19 N/A 7.1 HIGH
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.
CVE-2026-1068 1 Lenovo 1 Filez 2026-08-19 N/A 5.3 MEDIUM
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.
CVE-2026-0520 1 Lenovo 1 Filez 2026-08-19 N/A 2.8 LOW
A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.
CVE-2026-1717 1 Lenovo 1 Vantage 2026-06-17 N/A 5.5 MEDIUM
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.
CVE-2026-1716 1 Lenovo 1 Vantage 2026-06-17 N/A 7.1 HIGH
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.
CVE-2026-1715 1 Lenovo 1 Vantage 2026-06-17 N/A 7.1 HIGH
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
CVE-2025-8486 1 Lenovo 1 Pcmanager 2026-06-17 N/A 7.8 HIGH
A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.
CVE-2025-8485 1 Lenovo 1 App Store 2026-06-17 N/A 7.3 HIGH
An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.
CVE-2025-8098 1 Lenovo 1 Pcmanager 2026-06-17 N/A 7.8 HIGH
An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.