CVE Tools

Lenovo-group-limited

74 CVEs tracked since 2022. Since Apr 2022, none of them reached CISA KEV.

Lenovo-group-limited CVEs per month

Apr 2022 to Dec 2024. Point at a month, or focus the strip and use the arrow keys.
Lenovo-group-limited CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-04120
2022-0540
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01310
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-0140
2024-02null or fewer
2024-0350
2024-0470
2024-05null or fewer
2024-06null or fewer
2024-0770
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-1240

Products

The products that kept showing up in Lenovo-group-limited's monthly top three, with their CVEs summed over those months.

  1. SR645201 month
  2. SR665201 month
  3. SR635192 months
  4. HX1021 Edge Certified Node 3yr51 month
  5. HX1320 Appliance51 month
  6. HX1321 Certified Node51 month
  7. Legion 5 Pro-16ach641 month
  8. Legion 5-17ith641 month
  9. Legion 5-17ith6h41 month
  10. Lenovo Nextscale Enclosure - N1200 Enclosure41 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Lenovo-group-limited.

  1. CVE-2024-21944Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root o...5.3
  2. CVE-2025-8061A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated l...7.0
  3. CVE-2025-8557An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) n...8.8
  4. CVE-2025-9201A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that could allow a local user to execute code with elevated privileges.7.8
  5. CVE-2025-4371A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over...6.8
  6. CVE-2025-6249An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions access to application data.6.7
  7. CVE-2025-1729A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges.6.7
  8. CVE-2025-1700A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the so...7.0
  9. CVE-2025-0886An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate privileges.7.8
  10. CVE-2024-12673An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. T...7.8
  11. CVE-2024-6001An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with ele...8.1
  12. CVE-2024-4762An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.7.8
  13. CVE-2024-33056Buffer Over-read in MProc8.4
  14. CVE-2024-33044Improper Validation of Array Index in Hypervisor8.4
  15. CVE-2023-28149An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, and 5.6 before 05.60.39 tha...6.1

The record

Peak rank
#22 in Jan 2023
Busiest month shown
Jan 2023, 31 CVEs
Months with a KEV entry
0 since Apr 2022
Monthly snapshots
8 since 2022
Lenovo-group-limited's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store