Skip to main content

Vendor archive

lenovo CVEs

Beta · best-effort

400 CVEs tagged to vendor lenovo19 Critical, 160 High, 213 Medium, 8 Low, 0 Unrated.

CVE-2026-1717

Published Mar 11, 2026

An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to termin…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-1716

Published Mar 11, 2026

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arb…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-1715

Published Mar 11, 2026

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arb…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-13455

Published Jan 14, 2026

A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fing…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-13454

Published Jan 14, 2026

A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-13453

Published Jan 14, 2026

A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-8485

Published Nov 12, 2025

An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-8486

Published Oct 15, 2025

A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-10581

Published Oct 15, 2025

A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-8098

Published Aug 18, 2025

An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6232

Published Jul 17, 2025

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifyi…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6231

Published Jul 17, 2025

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifyi…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2503

Published May 30, 2025

An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2502

Published May 30, 2025

An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2501

Published May 30, 2025

An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9046

Published Oct 11, 2024

A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5474

Published Oct 11, 2024

A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacke…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4132

Published Oct 11, 2024

A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4131

Published Oct 11, 2024

A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4130

Published Oct 11, 2024

A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4089

Published Oct 11, 2024

A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45104

Published Sep 13, 2024

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45103

Published Sep 13, 2024

A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1577

Published Jul 31, 2024

A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 400 CVEsPage 1 of 16