Known Vulnerabilities for System Update by Lenovo
Listed below are 10 of the newest known vulnerabilities associated with "System Update" by "Lenovo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34746 | Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side R... | Not Provided | 2026-04-01 | 2026-04-02 |
| CVE-2026-33531 | InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-33530 | InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk d... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-31836 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and inci... | Not Provided | 2026-03-20 | 2026-03-20 |
| CVE-2026-27748 | Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the upda... | Not Provided | 2026-03-05 | 2026-04-01 |
| CVE-2026-20174 | A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacke... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-3775 | The application's update service, when checking for updates, loads certain system libraries from a search path that includes ... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2025-14777 | A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for authorizati... | Not Provided | 2025-12-16 | 2026-04-02 |
| CVE-2023-4632 | An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access... | 7.8 - HIGH | 2023-11-08 | 2023-11-16 |
| CVE-2022-4568 | A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges. | 7.8 - HIGH | 2023-05-01 | 2023-05-10 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lenovo | System Update | 5.07.0106 | |||
| Application | Lenovo | System Update | 5.07.0088 | |||
| Application | Lenovo | System Update | 5.07.0084 | |||
| Application | Lenovo | System Update | 5.07.0072 | |||
| Application | Lenovo | System Update | 5.07.0019 | |||
| Application | Lenovo | System Update | 5.07.0013 | |||
| Application | Lenovo | System Update | 5.07.0008 | |||
| Application | Lenovo | System Update | 5.06.0043 | |||
| Application | Lenovo | System Update | 5.06.0034 | |||
| Application | Lenovo | System Update | 5.06.0027 | |||
| Application | Lenovo | System Update | - |