Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 14 of 56
CVE-2021-37010P3HIGHCVSS 7.5v2.02021-11-23
CVE-2021-37010 [HIGH] CWE-200 CVE-2021-37010: There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartp
There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
nvd
CVE-2021-37014P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37014 [HIGH] CWE-787 CVE-2021-37014: There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to device cannot be used properly.
nvd
CVE-2022-34739P3HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34739 [HIGH] CVE-2022-34739: The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitati
The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings.
nvd
CVE-2021-37006P3HIGHCVSS 7.5v2.02021-11-23
CVE-2021-37006 [HIGH] CWE-281 CVE-2021-37006: There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploi
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
nvd
CVE-2022-31757P3HIGHCVSS 7.5v2.02022-06-13
CVE-2022-31757 [HIGH] CVE-2022-31757: The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vuln
The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2025-46588P3HIGHCVSS 7.7v5.0.02025-05-06
CVE-2025-46588 [HIGH] CWE-284 CVE-2025-46588: Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this
Vulnerability of unauthorized access in the app lock module
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2021-46856P3HIGHCVSS 7.5v2.0v3.0.02022-12-20
CVE-2021-46856 [HIGH] CWE-22 CVE-2021-46856: The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of
The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48346P3HIGHCVSS 7.5v2.0v2.0.1+4 more2023-03-27
CVE-2022-48346 [HIGH] CWE-200 CVE-2022-48346: The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerabilit
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-37005P3HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37005 [HIGH] CWE-88 CVE-2022-37005: The Settings application has an argument injection vulnerability. Successful exploitation of this vu
The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38979P3HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-38979 [HIGH] CVE-2022-38979: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38997P3HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-38997 [HIGH] CVE-2022-38997: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38994P3HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-38994 [HIGH] CVE-2022-38994: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38992P3HIGHCVSS 7.5v2.02022-09-16
CVE-2022-38992 [HIGH] CVE-2022-38992: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38991P3HIGHCVSS 7.5v2.02022-09-16
CVE-2022-38991 [HIGH] CVE-2022-38991: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38978P3HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-38978 [HIGH] CVE-2022-38978: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38988P3HIGHCVSS 7.5v2.02022-09-16
CVE-2022-38988 [HIGH] CVE-2022-38988: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-49242P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49242 [HIGH] CVE-2023-49242: Free broadcast vulnerability in the running management module. Successful exploitation of this vulne
Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46757P3HIGHCVSS 7.5v4.0.02023-11-08
CVE-2023-46757 [HIGH] CWE-200 CVE-2023-46757: The remote PIN module has a vulnerability that causes incorrect information storage locations.Succes
The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-49247P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49247 [HIGH] CWE-295 CVE-2023-49247: Permission verification vulnerability in distributed scenarios. Successful exploitation of this vuln
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46771P3HIGHCVSS 7.5v2.0.0v3.0.0+1 more2023-11-08
CVE-2023-46771 [HIGH] CWE-269 CVE-2023-46771: Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may
Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd