Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 36 of 56
CVE-2026-58555P4MEDIUMCVSS 6.6v6.1.02026-07-15
CVE-2026-58555 [MEDIUM] CWE-264 CVE-2026-58555: Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerab
Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52554P4MEDIUMCVSS 6.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52554 [MEDIUM] CWE-732 CVE-2023-52554: Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vu
Permission control vulnerability in the Bluetooth module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-31173P4MEDIUMCVSS 6.5v5.0.02025-04-07
CVE-2025-31173 [MEDIUM] CWE-280 CVE-2025-31173: Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitat
Memory write permission bypass vulnerability in the kernel futex module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41975P4MEDIUMCVSS 6.3v6.1.0v6.0.02026-06-09
CVE-2026-41975 [MEDIUM] CWE-701 CVE-2026-41975: Permission management vulnerability in the network management module. Impact: Successful exploitatio
Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2022-48613P4MEDIUMCVSS 5.9v2.0.0v3.0.02023-11-08
CVE-2022-48613 [MEDIUM] CWE-362 CVE-2022-48613: Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may
Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.
nvd
CVE-2024-56441P4MEDIUMCVSS 5.9v2.0.0v2.1.0+4 more2025-01-08
CVE-2024-56441 [MEDIUM] CWE-362 CVE-2024-56441: Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerabil
Race condition vulnerability in the Bastet module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54102P4MEDIUMCVSS 5.9v4.2.0v5.0.02024-12-12
CVE-2024-54102 [MEDIUM] CWE-362 CVE-2024-54102: Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability
Race condition vulnerability in the DDR module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41960P4MEDIUMCVSS 5.8v4.3.1v4.3.0+2 more2026-05-15
CVE-2026-41960 [MEDIUM] CWE-200 CVE-2026-41960: Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-37238P4MEDIUMCVSS 5.3v3.0.0v3.1.02023-07-06
CVE-2023-37238 [MEDIUM] CWE-275 CVE-2023-37238: Vulnerability of apps' permission to access a certain API being incompletely verified in the wireles
Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features.
nvd
CVE-2025-48908P4MEDIUMCVSS 6.7v5.0.2v5.0.02025-06-06
CVE-2025-48908 [MEDIUM] CWE-567 CVE-2025-48908: Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation
Ability Auto Startup service vulnerability in the foundation process
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-34741P4MEDIUMCVSS 6.5v2.02022-07-12
CVE-2022-34741 [MEDIUM] CWE-120 CVE-2022-34741: The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability ma
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
nvd
CVE-2022-34740P4MEDIUMCVSS 6.5v2.02022-07-12
CVE-2022-34740 [MEDIUM] CWE-120 CVE-2022-34740: The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability ma
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
nvd
CVE-2024-42030P4MEDIUMCVSS 6.2v3.1.0v4.0.0+1 more2024-08-08
CVE-2024-42030 [MEDIUM] CWE-701 CVE-2024-42030: Access permission verification vulnerability in the content sharing pop-up module Impact: Successful
Access permission verification vulnerability in the content sharing pop-up module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41969P4MEDIUMCVSS 6.2v4.3.1v4.3.0+2 more2026-05-15
CVE-2026-41969 [MEDIUM] CWE-275 CVE-2026-41969: Permission control vulnerability in the projection module. Impact: Successful exploitation of this v
Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48509P4MEDIUMCVSS 5.9v2.0.0v2.0.12023-07-06
CVE-2022-48509 [MEDIUM] CWE-476 CVE-2022-48509: Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Sh
Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally.
nvd
CVE-2026-34850P4MEDIUMCVSS 5.9v5.1.0v6.0.02026-04-13
CVE-2026-34850 [MEDIUM] CWE-362 CVE-2026-34850: Race condition vulnerability in the notification service. Impact: Successful exploitation of this vu
Race condition vulnerability in the notification service.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-54120P4MEDIUMCVSS 5.9v5.0.02025-01-08
CVE-2024-54120 [MEDIUM] CWE-362 CVE-2024-54120: Race condition vulnerability in the distributed notification module Impact: Successful exploitation
Race condition vulnerability in the distributed notification module
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2025-53168P4MEDIUMCVSS 5.7v5.0.1v5.1.02025-07-07
CVE-2025-53168 [MEDIUM] CWE-275 CVE-2025-53168: Vulnerability of bypassing the process to start SA and use related functions on distributed cameras
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras
Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.
nvd
CVE-2025-54618P4MEDIUMCVSS 5.7v5.0.1v5.0.2+1 more2025-08-06
CVE-2025-54618 [MEDIUM] CWE-275 CVE-2025-54618: Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitatio
Permission control vulnerability in the distributed clipboard module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-40009P4MEDIUMCVSS 5.3fixed in 2.0v2.02022-01-10
CVE-2021-40009 [MEDIUM] CWE-787 CVE-2021-40009: There is an Out-of-bounds write vulnerability in the AOD module in smartphones. Successful exploitat
There is an Out-of-bounds write vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
nvd