VYPR
Vendor

Lenovo

Products
2,498
CVEs
536
Across products
789
Status
Private

Products

2,498
View all 2,498 products →

Recent CVEs

536
View all 536 CVEs →
  • CVE-2017-5638CriKEVMar 11, 2017
    risk 0.86cvss 9.8epss 1.00

    The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type,…

  • CVE-2021-3897CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not…

  • CVE-2021-3849CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

  • CVE-2020-8349CriOct 14, 2020
    risk 0.64cvss 9.8epss 0.02

    An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is…

  • CVE-2015-5684CriMar 27, 2020
    risk 0.64cvss 9.8epss 0.04

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow…

  • CVE-2019-6188CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.01

    The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.

  • CVE-2019-6177CriAug 21, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that…

  • CVE-2019-6168CriJun 26, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.

  • CVE-2019-6167CriJun 26, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.

  • CVE-2018-9079CriSep 28, 2018
    risk 0.64cvss 9.8epss 0.01

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary…

  • CVE-2018-14066CriJul 15, 2018
    risk 0.64cvss 9.8epss 0.00

    The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as…

  • CVE-2017-17833CriApr 23, 2018
    risk 0.64cvss 9.8epss 0.04

    OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

  • CVE-2017-3774CriApr 19, 2018
    risk 0.64cvss 9.8epss 0.01

    A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and…

  • CVE-2017-3761CriOct 17, 2017
    risk 0.64cvss 9.8epss 0.04

    The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.

  • CVE-2017-3758CriOct 17, 2017
    risk 0.64cvss 9.8epss 0.03

    Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.

  • CVE-2016-8233CriMar 1, 2017
    risk 0.64cvss 9.8epss 0.01

    Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.

  • CVE-2021-3616CriAug 17, 2021
    risk 0.61cvss 9.4epss 0.01

    A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.

  • CVE-2026-16793HigAug 4, 2026
    risk 0.57cvss 8.8epss 0.00

    An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a…

  • CVE-2026-6281HigMay 13, 2026
    risk 0.57cvss 8.8epss 0.00

    A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

  • CVE-2025-8557HigSep 11, 2025
    risk 0.57cvss 8.8epss 0.00

    An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) network segment may be able to manipulate the local device to create an alternate…