VYPR

Vendor CVEs

Lenovo

All CVEs

536 total · sorted by risk
  • CVE-2026-1717MedMar 11, 2026
    risk 0.36cvss 5.5epss 0.00

    An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.

  • CVE-2026-1653MedMar 11, 2026
    risk 0.36cvss 5.5epss 0.00

    A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.

  • CVE-2025-13454MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.

  • CVE-2025-13154MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

  • CVE-2025-71108MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Handle incorrect num_connectors capability The UCSI spec states that the num_connectors field is 7 bits, and the 8th bit is reserved and should be set to zero. Some buggy FW has been known to…

  • CVE-2025-11193MedNov 3, 2025
    risk 0.36cvss 5.5epss 0.00

    A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sensitive device specific information.

  • CVE-2025-9548MedOct 15, 2025
    risk 0.36cvss 5.5epss 0.00

    A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticated user to cause a Windows blue screen error.

  • CVE-2024-5474MedOct 11, 2024
    risk 0.36cvss 5.5epss 0.00

    A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package.…

  • CVE-2017-3772MedJul 31, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

  • CVE-2023-6450MedJan 19, 2024
    risk 0.36cvss 5.5epss 0.00

    An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial of service.

  • CVE-2023-4891MedNov 8, 2023
    risk 0.36cvss 5.5epss 0.00

    A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service.

  • CVE-2022-1109MedJan 20, 2023
    risk 0.36cvss 5.5epss 0.00

    An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.

  • CVE-2022-1110MedMay 18, 2022
    risk 0.36cvss 5.5epss 0.00

    A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service.

  • CVE-2021-3721MedApr 22, 2022
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an attacker with local access to trigger a blue screen error.

  • CVE-2021-3720MedNov 12, 2021
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.

  • CVE-2021-3451MedApr 27, 2021
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations.

  • CVE-2021-3462MedApr 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.

  • CVE-2020-8357MedMar 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.

  • CVE-2020-8346MedSep 15, 2020
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.

  • CVE-2019-6163MedJun 26, 2019
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to non-standard locations.

  • CVE-2017-3747MedJun 29, 2017
    risk 0.36cvss 5.5epss 0.00

    Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.

  • CVE-2017-3740MedJun 4, 2017
    risk 0.36cvss 5.5epss 0.00

    In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.

  • CVE-2016-5248MedJun 30, 2016
    risk 0.36cvss 5.5epss 0.00

    The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument.

  • CVE-2025-9214MedSep 11, 2025
    risk 0.35cvss 5.4epss 0.00

    A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.

  • CVE-2023-2993MedJun 26, 2023
    risk 0.35cvss 5.4epss 0.00

    A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

  • CVE-2020-8330MedMay 28, 2020
    risk 0.35cvss 5.3epss 0.02

    A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, preventing subsequent print jobs until the printer is rebooted.

  • CVE-2020-8329MedMay 28, 2020
    risk 0.35cvss 5.3epss 0.02

    A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, causing an error to be displayed and preventing printer from functioning until…

  • CVE-2019-19757MedFeb 14, 2020
    risk 0.35cvss 5.4epss 0.01

    An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially…

  • CVE-2019-6178MedAug 19, 2019
    risk 0.35cvss 5.3epss 0.01

    An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file…

  • CVE-2019-6154MedApr 10, 2019
    risk 0.35cvss 5.3epss 0.01

    A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local access to execute code on the system.

  • CVE-2018-9071MedNov 16, 2018
    risk 0.35cvss 5.3epss 0.01

    Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.

  • CVE-2017-3764MedNov 30, 2017
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.

  • CVE-2015-8108MedApr 12, 2016
    risk 0.35cvss 5.3epss 0.01

    The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via…

  • CVE-2026-1068MedMar 11, 2026
    risk 0.34cvss 5.3epss 0.00

    An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.

  • CVE-2025-12047MedNov 12, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the same logical network to disclose sensitive user files from the application.

  • CVE-2025-10699MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.

  • CVE-2025-6230MedJul 17, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.

  • CVE-2025-1479MedMay 30, 2025
    risk 0.34cvss 5.3epss 0.00

    An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.

  • CVE-2024-27910MedApr 5, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.

  • CVE-2023-29056MedApr 28, 2023
    risk 0.34cvss 5.3epss 0.00

    A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.

  • CVE-2022-0636MedApr 22, 2022
    risk 0.33cvss 5.0epss 0.00

    A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.

  • CVE-2021-3722MedApr 22, 2022
    risk 0.33cvss 5.0epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be written to non-standard locations during installation.

  • CVE-2020-8324MedApr 14, 2020
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed.

  • CVE-2019-6190MedFeb 14, 2020
    risk 0.33cvss 5.0epss 0.00

    Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.

  • CVE-2024-27909MedApr 5, 2024
    risk 0.32cvss 4.9epss 0.01

    A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.

  • CVE-2024-27908MedApr 5, 2024
    risk 0.32cvss 4.9epss 0.01

    A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.

  • CVE-2023-25495MedApr 28, 2023
    risk 0.32cvss 4.9epss 0.01

    A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured

  • CVE-2021-3417MedMar 9, 2021
    risk 0.32cvss 4.9epss 0.01

    An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA. Affected…

  • CVE-2020-8356MedMar 9, 2021
    risk 0.32cvss 4.9epss 0.01

    An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected logs are captured in the First Failure Data Capture (FFDC)…

  • CVE-2020-8355MedFeb 10, 2021
    risk 0.32cvss 4.9epss 0.01

    An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if…