23 Total CVEs
23 AI Analyzed
0 CISA KEV
0 Critical

Profile

0% ended up actively exploited 0 of 23 added to CISA KEV
0% rated critical (CVSS 9.0+) 0 critical, 23 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

14 CVEs in the last 12 months

Products

  • Software Fix2
  • Personal Cloud1
  • XClarity Orchestrator1
  • XClarity Integrator for Microsoft Windows Admin Center1

4 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-23 of 23 CVEs
CVE-2026-6281
Analyzed
8.8
Lenovo Personal Cloud

A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network...

2026-05-14
CVE-2026-4145
Analyzed
7.8
Lenovo Software Fix

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to...

2026-04-17
CVE-2026-4134
Analyzed
7.3
Lenovo Software Fix

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local...

2026-04-17
CVE-2026-16793
Analyzed
8.8
Lenovo XClarity Orchestrator

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2

2026-08-05
CVE-2026-14371
Analyzed
8.8
Lenovo XClarity Integrator for Microsoft Windows Admin Center

The Lenovo XClarity Integrator for Windows Admin Center plugin version 5

2026-07-17
CVE-2025-9319
Analyzed
7.5
Lenovo Multiple Products

A potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under certain conditions

2025-09-12
CVE-2025-9201
Analyzed
7.8
Lenovo Multiple Products

A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that could allow a local user to execu...

2025-09-12
CVE-2025-8557
Analyzed
8.8
Lenovo Multiple Products

An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on...

2025-09-12
CVE-2025-8486
Analyzed
7.8
Lenovo Multiple Products

A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges

2025-10-16
CVE-2025-8485
Analyzed
7.3
Lenovo Multiple Products

An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privi...

2025-11-14
CVE-2025-8098
Analyzed
7.8
Lenovo Multiple Products

An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges

2025-08-19
CVE-2025-8061
Analyzed
7
Lenovo Multiple Products

A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3

2025-09-12
CVE-2025-6248
Analyzed
7.4
Lenovo Multiple Products

A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user v...

2025-07-17
CVE-2025-6232
Analyzed
7.8
Lenovo Multiple Products

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with el...

2025-07-17
CVE-2025-6231
Analyzed
7.8
Lenovo Multiple Products

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with el...

2025-07-17
CVE-2025-13455
Analyzed
7.8
Lenovo Multiple Products

A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication...

2026-01-16
CVE-2025-13155
Analyzed
7.8
Lenovo Multiple Products

An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated...

2025-12-11
CVE-2025-13152
Analyzed
7.8
Lenovo Multiple Products

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticate...

2025-12-11
CVE-2025-12048
Analyzed
7.5
Lenovo Multiple Products

An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote co...

2025-11-14
CVE-2025-12046
Analyzed
7.8
Lenovo Multiple Products

A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to exec...

2025-12-11
CVE-2025-10581
Analyzed
7.8
Lenovo Multiple Products

A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authen...

2025-10-16
CVE-2025-10495
Analyzed
7.5
Lenovo Multiple Products

A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, un...

2025-11-14
CVE-2025-0886
Analyzed
7.8
Lenovo Multiple Products

An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate priv...

2025-07-17