VYPR

Vendor CVEs

Lenovo

All CVEs

536 total · sorted by risk
  • CVE-2019-6192MedDec 10, 2019
    risk 0.32cvss 4.4epss 0.02

    A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.

  • CVE-2019-6182MedSep 3, 2019
    risk 0.32cvss 4.9epss 0.01

    A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV…

  • CVE-2018-9085MedNov 16, 2018
    risk 0.32cvss 4.9epss 0.01

    A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash…

  • CVE-2016-8226MedJan 26, 2017
    risk 0.32cvss 4.9epss 0.01

    The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure.

  • CVE-2024-10254MedJan 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.

  • CVE-2024-10253MedJan 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.

  • CVE-2021-42205MedNov 7, 2022
    risk 0.31cvss 4.7epss 0.00

    ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.

  • CVE-2019-6195MedFeb 14, 2020
    risk 0.31cvss 4.8epss 0.01

    An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication…

  • CVE-2019-6180MedSep 3, 2019
    risk 0.31cvss 4.8epss 0.01

    A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the user's web browser. The…

  • CVE-2018-9081MedSep 28, 2018
    risk 0.31cvss 4.7epss 0.01

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible…

  • CVE-2017-3742MedJul 17, 2017
    risk 0.31cvss 4.8epss 0.01

    In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker…

  • CVE-2025-13453MedJan 14, 2026
    risk 0.30cvss 4.6epss 0.00

    A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.

  • CVE-2024-11679MedApr 11, 2025
    risk 0.29cvss 4.4epss 0.00

    An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory.

  • CVE-2024-40975MedJul 12, 2024
    risk 0.29cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: platform/x86: x86-android-tablets: Unregister devices in reverse order Not all subsystems support a device getting removed while there are still consumers of the device with a reference to the device. One…

  • CVE-2023-43574MedNov 8, 2023
    risk 0.29cvss 4.4epss 0.00

    A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

  • CVE-2023-43572MedNov 8, 2023
    risk 0.29cvss 4.4epss 0.00

    A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

  • CVE-2023-43568MedNov 8, 2023
    risk 0.29cvss 4.4epss 0.00

    A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

  • CVE-2022-3698MedOct 25, 2023
    risk 0.29cvss 4.4epss 0.00

    A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.

  • CVE-2022-0353MedOct 25, 2023
    risk 0.29cvss 4.4epss 0.00

    A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.

  • CVE-2022-3745MedAug 23, 2023
    risk 0.29cvss 4.4epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI.

  • CVE-2022-3743MedAug 23, 2023
    risk 0.29cvss 4.4epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands.

  • CVE-2022-40136MedJan 30, 2023
    risk 0.29cvss 4.4epss 0.00

    An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

  • CVE-2022-40135MedJan 30, 2023
    risk 0.29cvss 4.4epss 0.00

    An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

  • CVE-2022-40134MedJan 30, 2023
    risk 0.29cvss 4.4epss 0.00

    An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

  • CVE-2021-3786MedNov 12, 2021
    risk 0.29cvss 4.4epss 0.00

    A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.

  • CVE-2021-3473MedApr 13, 2021
    risk 0.29cvss 4.5epss 0.00

    An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore. The backup/restore…

  • CVE-2020-8316MedApr 14, 2020
    risk 0.29cvss 4.4epss 0.00

    A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the system with elevated privileges.

  • CVE-2016-8222MedNov 30, 2016
    risk 0.29cvss 4.4epss 0.00

    A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow…

  • CVE-2016-8224MedNov 29, 2016
    risk 0.29cvss 4.4epss 0.00

    A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or…

  • CVE-2026-7516MedJun 10, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents.

  • CVE-2024-8059MedSep 13, 2024
    risk 0.28cvss 4.3epss 0.00

    IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.

  • CVE-2024-45103MedSep 13, 2024
    risk 0.28cvss 4.3epss 0.00

    A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.

  • CVE-2022-34887MedOct 27, 2023
    risk 0.28cvss 4.3epss 0.00

    Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.

  • CVE-2021-42848MedMay 18, 2022
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.

  • CVE-2021-3956MedMay 18, 2022
    risk 0.28cvss 4.3epss 0.01

    A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such…

  • CVE-2021-3718MedNov 12, 2021
    risk 0.28cvss 4.3epss 0.00

    A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.

  • CVE-2023-4608MedOct 25, 2023
    risk 0.27cvss 4.1epss 0.00

    An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

  • CVE-2021-3463MedApr 13, 2021
    risk 0.27cvss 4.2epss 0.00

    A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause systems to experience a blue screen error.

  • CVE-2015-7269MedNov 27, 2017
    risk 0.27cvss 4.2epss 0.00

    Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by attaching a second SATA connector to exposed pins, maintaining an alternate…

  • CVE-2015-7267MedNov 27, 2017
    risk 0.27cvss 4.2epss 0.00

    Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with…

  • CVE-2016-1490MedJan 26, 2016
    risk 0.27cvss 4.1epss 0.02

    The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a crafted file request to /list.

  • CVE-2026-16791LowAug 4, 2026
    risk 0.25cvss 3.9epss 0.00

    A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated…

  • CVE-2025-2818LowJul 17, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired…

  • CVE-2025-14058LowJan 14, 2026
    risk 0.21cvss 3.2epss 0.00

    A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

  • CVE-2023-5081LowJan 19, 2024
    risk 0.21cvss 3.3epss 0.00

    An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier.

  • CVE-2019-6156LowApr 10, 2019
    risk 0.21cvss 3.3epss 0.00

    In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in…

  • CVE-2017-3741LowJun 4, 2017
    risk 0.21cvss 3.3epss 0.00

    In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.

  • CVE-2025-6026LowOct 15, 2025
    risk 0.20cvss 3.1epss 0.00

    An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.

  • CVE-2026-0520LowMar 11, 2026
    risk 0.18cvss 2.8epss 0.00

    A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.

  • CVE-2024-4786LowJul 26, 2024
    risk 0.18cvss 2.8epss 0.00

    An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.

Page 10 of 11