Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 43 of 56
CVE-2025-54624P4MEDIUMCVSS 5.7v5.0.1v5.0.2+1 more2025-08-06
CVE-2025-54624 [MEDIUM] CWE-275 CVE-2025-54624: Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitat
Unexpected injection event vulnerability in the multimodalinput module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-31756P4MEDIUMCVSS 5.5v2.02022-06-13
CVE-2022-31756 [MEDIUM] CVE-2022-31756: The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may
The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2024-32996P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-05-14
CVE-2024-32996 [MEDIUM] CWE-264 CVE-2024-32996: Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vul
Privilege escalation vulnerability in the account module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2021-22463P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22463 [MEDIUM] CWE-416 CVE-2021-22463: A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this v
A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.
nvd
CVE-2021-22467P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22467 [MEDIUM] CWE-20 CVE-2021-22467: A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may expl
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
nvd
CVE-2021-22452P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22452 [MEDIUM] CWE-20 CVE-2021-22452: A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may expl
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
nvd
CVE-2022-41590P4MEDIUMCVSS 5.5v3.0.02022-12-20
CVE-2022-41590 [MEDIUM] CWE-287 CVE-2022-41590: Some smartphones have authentication-related (including session management) vulnerabilities as the s
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.
nvd
CVE-2024-51528P4MEDIUMCVSS 5.5v3.0.0v3.1.0+2 more2024-11-05
CVE-2024-51528 [MEDIUM] CWE-532 CVE-2024-51528: Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitati
Vulnerability of improper log printing in the Super Home Screen module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-51530P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-11-05
CVE-2024-51530 [MEDIUM] CWE-20 CVE-2024-51530: LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerabi
LaunchAnywhere vulnerability in the account module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-42034P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-08-08
CVE-2024-42034 [MEDIUM] CWE-840 CVE-2024-42034: LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerab
LaunchAnywhere vulnerability in the account module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-8298P4MEDIUMCVSS 5.5v4.0.0v4.2.02024-09-04
CVE-2024-8298 [MEDIUM] CWE-701 CVE-2024-8298: Memory request vulnerability in the memory management module Impact: Successful exploitation of this
Memory request vulnerability in the memory management module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-36501P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-06-14
CVE-2024-36501 [MEDIUM] CWE-787 CVE-2024-36501: Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulne
Memory management vulnerability in the boottime module
Impact: Successful exploitation of this vulnerability can affect integrity.
nvd
CVE-2024-42032P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-08-08
CVE-2024-42032 [MEDIUM] CWE-285 CVE-2024-42032: Access permission verification vulnerability in the Contacts module Impact: Successful exploitation
Access permission verification vulnerability in the Contacts module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-39670P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-07-25
CVE-2024-39670 [MEDIUM] CWE-264 CVE-2024-39670: Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploit
Privilege escalation vulnerability in the account synchronisation module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-58252P4MEDIUMCVSS 5.5v5.0.02025-05-06
CVE-2024-58252 [MEDIUM] CWE-200 CVE-2024-58252: Vulnerability of insufficient information protection in the media library module Impact: Successful
Vulnerability of insufficient information protection in the media library module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-36499P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-06-14
CVE-2024-36499 [MEDIUM] CWE-269 CVE-2024-36499: Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation
Vulnerability of unauthorized screenshot capturing in the WMS module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-24919P4MEDIUMCVSS 5.5v4.0.0v4.2.0+2 more2026-02-06
CVE-2026-24919 [MEDIUM] CWE-787 CVE-2026-24919: Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnera
Out-of-bounds write vulnerability in the DFX module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54615P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54615 [MEDIUM] CWE-200 CVE-2025-54615: Vulnerability of insufficient information protection in the media library module. Impact: Successful
Vulnerability of insufficient information protection in the media library module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-54611P4MEDIUMCVSS 5.5v2.0.0v2.1.0+6 more2025-08-06
CVE-2025-54611 [MEDIUM] CWE-840 CVE-2025-54611: EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of
EXTRA_REFERRER resource read vulnerability in the Gallery module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-24931P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-02-06
CVE-2026-24931 [MEDIUM] CWE-264 CVE-2026-24931: Vulnerability of improper criterion security check in the card module. Impact: Successful exploitati
Vulnerability of improper criterion security check in the card module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd