Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 10 of 56
CVE-2023-49240P3HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49240 [HIGH] CWE-601 CVE-2023-49240: Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerabil
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-31174P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2025-31174 [HIGH] CWE-22 CVE-2025-31174: Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability
Path traversal vulnerability in the DFS module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48515P3HIGHCVSS 7.5v2.0.0v2.0.1+1 more2023-07-06
CVE-2022-48515 [HIGH] CWE-269 CVE-2022-48515: Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnera
Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44111P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44111 [HIGH] CWE-307 CVE-2023-44111: Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44096P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44096 [HIGH] CWE-287 CVE-2023-44096: Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44097P3HIGHCVSS 7.5v2.0.1v3.0.02023-10-11
CVE-2023-44097 [HIGH] CWE-200 CVE-2023-44097: Vulnerability of the permission to access device SNs being improperly managed.Successful exploitatio
Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-27895P3HIGHCVSS 7.5v4.0.02024-04-08
CVE-2024-27895 [HIGH] CWE-284 CVE-2024-27895: Vulnerability of permission control in the window module. Successful exploitation of this vulnerabil
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-52374P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-02-18
CVE-2023-52374 [HIGH] CWE-863 CVE-2023-52374: Permission control vulnerability in the package management module.Successful exploitation of this vu
Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52379P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52379 [HIGH] CWE-276 CVE-2023-52379: Permission control vulnerability in the calendarProvider module.Successful exploitation of this vuln
Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-39394P3HIGHCVSS 7.5v2.0.1v3.0.0+1 more2023-08-13
CVE-2023-39394 [HIGH] CWE-264 CVE-2023-39394: Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this
Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.
nvd
CVE-2026-28552P3HIGHCVSS 7.5v4.0.0v4.2.0+4 more2026-03-05
CVE-2026-28552 [HIGH] CWE-19 CVE-2026-28552: Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnera
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-46892P3HIGHCVSS 7.5v2.0.02023-07-06
CVE-2021-46892 [HIGH] CWE-701 CVE-2021-46892: Encryption bypass vulnerability in Maintenance mode. Successful exploitation of this vulnerability m
Encryption bypass vulnerability in Maintenance mode. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-56447P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2025-01-08
CVE-2024-56447 [HIGH] CWE-269 CVE-2024-56447: Vulnerability of improper permission control in the window management module Impact: Successful expl
Vulnerability of improper permission control in the window management module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52955P3HIGHCVSS 7.5v2.0.0v2.1.0+2 more2025-01-08
CVE-2023-52955 [HIGH] CWE-264 CVE-2023-52955: Vulnerability of improper authentication in the ANS system service module Impact: Successful exploit
Vulnerability of improper authentication in the ANS system service module
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2022-48478P3CRITICALCVSS 9.8v2.0v2.0.02023-05-26
CVE-2022-48478 [CRITICAL] CVE-2022-48478: The facial recognition TA of some products lacks memory length verification. Successful exploitation
The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
nvd
CVE-2024-9136P3HIGHCVSS 7.5v4.0.0v4.2.02024-09-27
CVE-2024-9136 [HIGH] CWE-863 CVE-2024-9136: Access permission verification vulnerability in the App Multiplier module Impact: Successful exploit
Access permission verification vulnerability in the App Multiplier module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-45450P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-09-04
CVE-2024-45450 [HIGH] CWE-200 CVE-2024-45450: Permission control vulnerability in the software update module. Impact: Successful exploitation of t
Permission control vulnerability in the software update module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-34853P3HIGHCVSS 7.5v4.0.0v4.2.0+2 more2026-04-13
CVE-2026-34853 [HIGH] CWE-270 CVE-2026-34853: Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerabi
Permission bypass vulnerability in the LBS module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-42036P3HIGHCVSS 7.5v3.0.0v3.1.0+2 more2024-08-08
CVE-2024-42036 [HIGH] CWE-285 CVE-2024-42036: Access permission verification vulnerability in the Notepad module Impact: Successful exploitation o
Access permission verification vulnerability in the Notepad module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37065P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-07
CVE-2021-37065 [CRITICAL] CWE-190 CVE-2021-37065: There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality or Availability impacted.
nvd