Known Vulnerabilities for System Update by Lenovo
Listed below are 10 of the newest known vulnerabilities associated with "System Update" by "Lenovo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-45228 json | Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the temp... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-44569 json | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, there's a... | Not Provided | 2026-05-15 | 2026-05-15 |
| CVE-2026-44224 json | Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary... | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-43410 json | In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-rsu: Fix NULL pointer dereference wh... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-43404 json | In the Linux kernel, the following vulnerability has been resolved: mm: Fix a hmm_range_fault() livelock / starvation proble... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-43363 json | In the Linux kernel, the following vulnerability has been resolved: x86/apic: Disable x2apic on resume if the kernel expects... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-43318 json | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_not... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-42843 json | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-42287 json | Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-42174 json | Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and d... | Not Provided | 2026-05-09 | 2026-05-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lenovo | System Update | 5.07.0106 | |||
| Application | Lenovo | System Update | 5.07.0088 | |||
| Application | Lenovo | System Update | 5.07.0084 | |||
| Application | Lenovo | System Update | 5.07.0072 | |||
| Application | Lenovo | System Update | 5.07.0019 | |||
| Application | Lenovo | System Update | 5.07.0013 | |||
| Application | Lenovo | System Update | 5.07.0008 | |||
| Application | Lenovo | System Update | 5.06.0043 | |||
| Application | Lenovo | System Update | 5.06.0034 | |||
| Application | Lenovo | System Update | 5.06.0027 | |||
| Application | Lenovo | System Update | - |