Known vulnerabilities in ThinkPad X1 Extreme 4th Gen 20Y5

Vendor: Lenovo
Software CPE: cpe:2.3:h:lenovo:thinkpad_x1_extreme_4th_gen_20y5:*:*:*:*:*:*:*:*
Total vulnerabilities: 114
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ThinkPad X1 Extreme 4th Gen 20Y5 ThinkPad X1 Extreme 4th Gen 20Y5 is affected by 114 known vulnerabilities: 15 medium, 99 low Critical High Medium Low

Vulnerabilities (114)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119817 - State Issues
CVE-2025-9614
CWE-371 Low
No
No
- 10.12.2025 SB20251210202
SB2025122701
#VU119816 - Insufficient Technical Documentation
CVE-2025-9613
CWE-1059 Low
No
No
- 10.12.2025 SB20251210202
SB2025122701
#VU119815 - Improper Validation of Integrity Check Value
CVE-2025-9612
CWE-354 Low
No
No
- 10.12.2025 SB20251210202
SB2025122701
#VU119804 - Exposure of sensitive information to an unauthorized actor
CVE-2024-38798
CWE-200 Low
No
No
- 10.12.2025 SB20251210176
SB2025122701
SB2026020648
and 2 more
#VU119030 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-47319
CWE-497 Low
No
No
- 02.12.2025 SB2025120232
SB2025122701
#VU119032 - Integer overflow
CVE-2025-47323
CWE-190 Low
No
No
- 02.12.2025 SB2025120232
SB2025122701
#VU118548 - Improper input validation
CVE-2025-25216
CWE-20 Low
No
No
- 14.11.2025 SB2025111455
SB2025122704
SB2026010556
#VU118547 - Untrusted Search Path
CVE-2025-31647
CWE-426 Low
No
No
- 14.11.2025 SB2025111455
SB2025122704
SB2026010556
#VU118546 - Incorrect Default Permissions
CVE-2025-32091
CWE-276 Low
No
No
- 14.11.2025 SB2025111455
SB2025122704
#VU116985 - Access of Uninitialized Pointer
CVE-2025-23352
CWE-824 Low
No
No
- 14.10.2025 SB2025101449
SB2025122911
#VU116984 - NULL Pointer Dereference
CVE-2025-23332
CWE-476 Low
No
No
- 14.10.2025 SB2025101448
SB2025122911
#VU116983 - NULL Pointer Dereference
CVE-2025-23330
CWE-476 Low
No
No
- 14.10.2025 SB2025101448
SB2025122911
#VU116982 - NULL Pointer Dereference
CVE-2025-23300
CWE-476 Low
No
No
- 14.10.2025 SB2025101448
SB2025122911
#VU116981 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-23282
CWE-362 Low
No
No
- 14.10.2025 SB2025101448
SB2025122911
#VU116980 - Use After Free
CVE-2025-23280
CWE-416 Low
No
No
- 14.10.2025 SB2025101448
SB2025122911
#VU116979 - Out-of-bounds read
CVE-2025-23345
CWE-125 Low
No
No
- 14.10.2025 SB2025101447
SB2025101448
SB2025122911
#VU116978 - Incorrect Default Permissions
CVE-2025-23347
CWE-276 Low
No
No
- 14.10.2025 SB2025101447
SB2025122911
#VU116977 - Uncontrolled Search Path Element
CVE-2025-23309
CWE-427 Low
No
No
- 14.10.2025 SB2025101447
SB2025122911
#VU114197 - Incorrect Default Permissions
CVE-2025-20023
CWE-276 Low
No
No
- 18.08.2025 SB2025081887
SB2025083023
#VU114178 - Information Exposure Through Log Files
CVE-2025-24520
CWE-532 Low
No
No
- 18.08.2025 SB2025081859
SB2025083026


Showing elements 1 - 20 out of 114