Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 35 of 56
CVE-2026-24916P4MEDIUMCVSS 5.5v6.0.02026-02-06
CVE-2026-24916 [MEDIUM] CWE-200 CVE-2026-24916: Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation o
Identity authentication bypass vulnerability in the window module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-56445P4MEDIUMCVSS 5.3v5.0.02025-01-08
CVE-2024-56445 [MEDIUM] CWE-287 CVE-2024-56445: Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploit
Instruction authentication bypass vulnerability in the Findnetwork module
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2024-39672P4HIGHCVSS 7.1v4.0.0v4.2.02024-07-25
CVE-2024-39672 [HIGH] CWE-416 CVE-2024-39672: Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vul
Memory request logic vulnerability in the memory module.
Impact: Successful exploitation of this vulnerability will affect integrity and availability.
nvd
CVE-2025-54606P4HIGHCVSS 7.1v5.0.1v5.0.22025-08-06
CVE-2025-54606 [HIGH] CWE-840 CVE-2025-54606: Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this
Status verification vulnerability in the lock screen module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2025-58311P4HIGHCVSS 7.1v4.0.0v4.2.0+4 more2025-11-28
CVE-2025-58311 [HIGH] CWE-416 CVE-2025-58311: UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability wi
UAF vulnerability in the USB driver module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2026-34859P4HIGHCVSS 7.1v4.2.0v4.3.02026-04-13
CVE-2026-34859 [HIGH] CWE-416 CVE-2026-34859: UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will a
UAF vulnerability in the kernel module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2023-34157P4MEDIUMCVSS 6.5fixed in 2.0v2.0.02023-06-16
CVE-2023-34157 [MEDIUM] CWE-290 CVE-2023-34157: Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may caus
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
nvd
CVE-2026-58554P4MEDIUMCVSS 6.6v4.3.1v4.3.0+2 more2026-07-15
CVE-2026-58554 [MEDIUM] CWE-200 CVE-2026-58554: Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vul
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41965P4MEDIUMCVSS 5.6v6.1.0v6.0.02026-05-15
CVE-2026-41965 [MEDIUM] CWE-840 CVE-2026-41965: Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability
Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-41966P4MEDIUMCVSS 5.6v6.1.0v6.0.0+1 more2026-05-15
CVE-2026-41966 [MEDIUM] CWE-840 CVE-2026-41966: Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of th
Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-58305P4MEDIUMCVSS 5.5v5.0.12025-11-28
CVE-2025-58305 [MEDIUM] CWE-200 CVE-2025-58305: Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of
Identity authentication bypass vulnerability in the Gallery app.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-22469P4HIGHCVSS 7.1v2.02021-10-28
CVE-2021-22469 [HIGH] CWE-125 CVE-2021-22469: A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit thi
A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.
nvd
CVE-2024-39673P4HIGHCVSS 7.1v2.0.0v2.1.0+4 more2024-07-25
CVE-2024-39673 [HIGH] CWE-502 CVE-2024-39673: Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exp
Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41976P4MEDIUMCVSS 6.6v4.3.1v4.3.02026-06-09
CVE-2026-41976 [MEDIUM] CWE-275 CVE-2026-41976: Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vul
Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48314P4MEDIUMCVSS 6.5v2.0v2.1+5 more2023-04-16
CVE-2022-48314 [MEDIUM] CWE-287 CVE-2022-48314: The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process.
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48313P4MEDIUMCVSS 6.5v2.0v2.1+5 more2023-04-16
CVE-2022-48313 [MEDIUM] CWE-639 CVE-2022-48313: The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process.
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2025-54653P4MEDIUMCVSS 6.5v5.0.1v5.0.22025-08-06
CVE-2025-54653 [MEDIUM] CWE-22 CVE-2025-54653: Path traversal vulnerability in the virtualization file module. Successful exploitation of this vuln
Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization file module.
nvd
CVE-2021-40055P4MEDIUMCVSS 5.9v2.02022-03-10
CVE-2021-40055 [MEDIUM] CVE-2021-40055: There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Su
There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity.
nvd
CVE-2022-44563P4MEDIUMCVSS 5.9v2.0v2.12022-11-09
CVE-2022-44563 [MEDIUM] CWE-362 CVE-2022-44563: There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerab
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2025-58278P4MEDIUMCVSS 5.5v5.0.12025-10-11
CVE-2025-58278 [MEDIUM] CWE-200 CVE-2025-58278: Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vul
Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.
nvd