lenovo
Latest CVEs
The 15 most recently published vulnerabilities affecting lenovo.
- CVE-2026-16793Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator8.8
- CVE-2026-16792Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator6.1
- CVE-2026-16791Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI3.9
- CVE-2026-10590A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.4.4
- CVE-2026-10589A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.6.0
- CVE-2026-10588A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.4.4
- CVE-2026-10587A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.6.0
- CVE-2026-13104A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privil...7.3
- CVE-2026-13103A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.7.3
- CVE-2026-9046A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a no...7.0
- CVE-2026-6511During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access fi...5.5
- CVE-2025-10238During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in Sy...6.7
- CVE-2025-10237During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or...6.7
- CVE-2026-6090A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.7.0
- CVE-2026-8637A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privi...7.8