Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 1 of 56
CVE-2023-37242P3CRITICALCVSS 9.8v2.0v3.0.0+1 more2023-07-06
CVE-2023-37242 [CRITICAL] CWE-639 CVE-2023-37242: Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
nvd
CVE-2025-54617P3CRITICALCVSS 9.8v5.1.02025-08-06
CVE-2025-54617 [CRITICAL] CWE-121 CVE-2025-54617: Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of
Stack-based buffer overflow vulnerability in the dms_fwk module.
Impact: Successful exploitation of this vulnerability can cause RCE.
nvd
CVE-2023-52381P3CRITICALCVSS 9.8v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52381 [CRITICAL] CWE-94 CVE-2023-52381: Script injection vulnerability in the email module.Successful exploitation of this vulnerability may
Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
nvd
CVE-2026-28536P3HIGHCVSS 8.1v5.1.0v6.0.02026-03-05
CVE-2026-28536 [HIGH] CWE-305 CVE-2026-28536: Authentication bypass vulnerability in the device authentication module. Impact: Successful exploita
Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2021-37095P3CRITICALCVSS 9.8fixed in 2.0v2.02021-12-07
CVE-2021-37095 [CRITICAL] CWE-190 CVE-2021-37095: There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution.
nvd
CVE-2025-48906P3HIGHCVSS 8.8v5.0.02025-06-06
CVE-2025-48906 [HIGH] CWE-290 CVE-2025-48906: Authentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this v
Authentication bypass vulnerability in the DSoftBus module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58124P3CRITICALCVSS 9.1v4.0.02025-04-07
CVE-2024-58124 [CRITICAL] CWE-290 CVE-2024-58124: Access control vulnerability in the security verification module Impact: Successful exploitation of
Access control vulnerability in the security verification module
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2024-58126P3CRITICALCVSS 9.1v4.0.0v4.3.02025-04-07
CVE-2024-58126 [CRITICAL] CWE-290 CVE-2024-58126: Access control vulnerability in the security verification module Impact: Successful exploitation of
Access control vulnerability in the security verification module
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2024-58127P3CRITICALCVSS 9.1v4.0.0v4.3.02025-04-07
CVE-2024-58127 [CRITICAL] CWE-290 CVE-2024-58127: Access control vulnerability in the security verification module Impact: Successful exploitation of
Access control vulnerability in the security verification module
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2025-31170P3CRITICALCVSS 9.1v4.0.0v4.3.0+1 more2025-04-07
CVE-2025-31170 [CRITICAL] CWE-290 CVE-2025-31170: Access control vulnerability in the security verification module Impact: Successful exploitation of
Access control vulnerability in the security verification module
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2024-58125P3CRITICALCVSS 9.1v4.0.0v4.3.02025-04-07
CVE-2024-58125 [CRITICAL] CWE-290 CVE-2024-58125: Access control vulnerability in the security verification module Impact: Successful exploitation of
Access control vulnerability in the security verification module
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2021-37128P3CRITICALCVSS 9.8fixed in 2.0v2.02022-01-03
CVE-2021-37128 [CRITICAL] CWE-22 CVE-2021-37128: HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may
HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.
nvd
CVE-2021-37040P3CRITICALCVSS 9.8fixed in 2.0v2.02021-12-08
CVE-2021-37040 [CRITICAL] CWE-88 CVE-2021-37040: There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vu
There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting.
nvd
CVE-2022-38983P3CRITICALCVSS 9.8v2.0v2.12022-10-14
CVE-2022-38983 [CRITICAL] CWE-416 CVE-2022-38983: The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vu
The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution.
nvd
CVE-2021-39979P3CRITICALCVSS 9.8fixed in 2.0v2.02022-01-03
CVE-2021-39979 [CRITICAL] CWE-94 CVE-2021-39979: HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may aff
HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.
nvd
CVE-2021-22432P3CRITICALCVSS 9.8v2.02022-02-25
CVE-2021-22432 [CRITICAL] CWE-119 CVE-2021-22432: There is a vulnerability when configuring permission isolation in smartphones. Successful exploitati
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
nvd
CVE-2021-22430P3CRITICALCVSS 9.8v2.02022-02-25
CVE-2021-22430 [CRITICAL] CVE-2021-22430: There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability
There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.
nvd
CVE-2021-22431P3CRITICALCVSS 9.8v2.02022-02-25
CVE-2021-22431 [CRITICAL] CWE-119 CVE-2021-22431: There is a vulnerability when configuring permission isolation in smartphones. Successful exploitati
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
nvd
CVE-2023-46773P3CRITICALCVSS 9.8v3.0.0v3.1.0+1 more2023-12-06
CVE-2023-46773 [CRITICAL] CWE-276 CVE-2023-46773: Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability
Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2023-52378P3CRITICALCVSS 9.8v3.0.0v3.1.02024-02-18
CVE-2023-52378 [CRITICAL] CWE-693 CVE-2023-52378: Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation
Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
1 / 56Next →