CVE-2026-15994
- EPSS 0.16%
- Veröffentlicht 13.08.2026 14:53:05
- Zuletzt bearbeitet 24.08.2026 16:45:25
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.
CVE-2026-12036
- EPSS 0.16%
- Veröffentlicht 13.08.2026 14:52:27
- Zuletzt bearbeitet 24.08.2026 16:45:25
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.
CVE-2026-0827
- EPSS 0.2%
- Veröffentlicht 15.04.2026 12:27:45
- Zuletzt bearbeitet 24.08.2026 17:18:57
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to p...
CVE-2026-1717
- EPSS 0.14%
- Veröffentlicht 11.03.2026 20:22:50
- Zuletzt bearbeitet 25.03.2026 18:22:49
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.
CVE-2026-1716
- EPSS 0.15%
- Veröffentlicht 11.03.2026 20:22:37
- Zuletzt bearbeitet 25.03.2026 18:23:11
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.
CVE-2026-1715
- EPSS 0.15%
- Veröffentlicht 11.03.2026 20:22:24
- Zuletzt bearbeitet 25.03.2026 18:23:21
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
CVE-2025-13154
- EPSS 0.12%
- Veröffentlicht 14.01.2026 22:16:13
- Zuletzt bearbeitet 15.04.2026 00:35:42
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
CVE-2025-6232
- EPSS 0.19%
- Veröffentlicht 17.07.2025 19:19:32
- Zuletzt bearbeitet 22.07.2025 17:05:42
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
CVE-2025-6231
- EPSS 0.19%
- Veröffentlicht 17.07.2025 19:19:23
- Zuletzt bearbeitet 22.07.2025 17:05:25
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
CVE-2025-6230
- EPSS 0.15%
- Veröffentlicht 17.07.2025 19:19:12
- Zuletzt bearbeitet 19.08.2025 16:32:52
A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.