cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 35 of 56
CVE-2026-24916P4MEDIUMCVSS 5.5v6.0.02026-02-06
CVE-2026-24916 [MEDIUM] CWE-200 CVE-2026-24916: Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation o Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-56445P4MEDIUMCVSS 5.3v5.0.02025-01-08
CVE-2024-56445 [MEDIUM] CWE-287 CVE-2024-56445: Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploit Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2024-39672P4HIGHCVSS 7.1v4.0.0v4.2.02024-07-25
CVE-2024-39672 [HIGH] CWE-416 CVE-2024-39672: Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vul Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
nvd
CVE-2025-54606P4HIGHCVSS 7.1v5.0.1v5.0.22025-08-06
CVE-2025-54606 [HIGH] CWE-840 CVE-2025-54606: Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2025-58311P4HIGHCVSS 7.1v4.0.0v4.2.0+4 more2025-11-28
CVE-2025-58311 [HIGH] CWE-416 CVE-2025-58311: UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability wi UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2026-34859P4HIGHCVSS 7.1v4.2.0v4.3.02026-04-13
CVE-2026-34859 [HIGH] CWE-416 CVE-2026-34859: UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will a UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2023-34157P4MEDIUMCVSS 6.5fixed in 2.0v2.0.02023-06-16
CVE-2023-34157 [MEDIUM] CWE-290 CVE-2023-34157: Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may caus Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
nvd
CVE-2026-58554P4MEDIUMCVSS 6.6v4.3.1v4.3.0+2 more2026-07-15
CVE-2026-58554 [MEDIUM] CWE-200 CVE-2026-58554: Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vul Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41965P4MEDIUMCVSS 5.6v6.1.0v6.0.02026-05-15
CVE-2026-41965 [MEDIUM] CWE-840 CVE-2026-41965: Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-41966P4MEDIUMCVSS 5.6v6.1.0v6.0.0+1 more2026-05-15
CVE-2026-41966 [MEDIUM] CWE-840 CVE-2026-41966: Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of th Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-58305P4MEDIUMCVSS 5.5v5.0.12025-11-28
CVE-2025-58305 [MEDIUM] CWE-200 CVE-2025-58305: Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-22469P4HIGHCVSS 7.1v2.02021-10-28
CVE-2021-22469 [HIGH] CWE-125 CVE-2021-22469: A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit thi A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.
nvd
CVE-2024-39673P4HIGHCVSS 7.1v2.0.0v2.1.0+4 more2024-07-25
CVE-2024-39673 [HIGH] CWE-502 CVE-2024-39673: Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exp Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41976P4MEDIUMCVSS 6.6v4.3.1v4.3.02026-06-09
CVE-2026-41976 [MEDIUM] CWE-275 CVE-2026-41976: Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vul Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48314P4MEDIUMCVSS 6.5v2.0v2.1+5 more2023-04-16
CVE-2022-48314 [MEDIUM] CWE-287 CVE-2022-48314: The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48313P4MEDIUMCVSS 6.5v2.0v2.1+5 more2023-04-16
CVE-2022-48313 [MEDIUM] CWE-639 CVE-2022-48313: The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2025-54653P4MEDIUMCVSS 6.5v5.0.1v5.0.22025-08-06
CVE-2025-54653 [MEDIUM] CWE-22 CVE-2025-54653: Path traversal vulnerability in the virtualization file module. Successful exploitation of this vuln Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization file module.
nvd
CVE-2021-40055P4MEDIUMCVSS 5.9v2.02022-03-10
CVE-2021-40055 [MEDIUM] CVE-2021-40055: There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Su There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity.
nvd
CVE-2022-44563P4MEDIUMCVSS 5.9v2.0v2.12022-11-09
CVE-2022-44563 [MEDIUM] CWE-362 CVE-2022-44563: There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerab There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2025-58278P4MEDIUMCVSS 5.5v5.0.12025-10-11
CVE-2025-58278 [MEDIUM] CWE-200 CVE-2025-58278: Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vul Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
Huawei Harmonyos vulnerabilities | cvebase