cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 43 of 56
CVE-2025-54624P4MEDIUMCVSS 5.7v5.0.1v5.0.2+1 more2025-08-06
CVE-2025-54624 [MEDIUM] CWE-275 CVE-2025-54624: Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitat Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-31756P4MEDIUMCVSS 5.5v2.02022-06-13
CVE-2022-31756 [MEDIUM] CVE-2022-31756: The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2024-32996P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-05-14
CVE-2024-32996 [MEDIUM] CWE-264 CVE-2024-32996: Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vul Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2021-22463P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22463 [MEDIUM] CWE-416 CVE-2021-22463: A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this v A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.
nvd
CVE-2021-22467P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22467 [MEDIUM] CWE-20 CVE-2021-22467: A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may expl A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
nvd
CVE-2021-22452P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22452 [MEDIUM] CWE-20 CVE-2021-22452: A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may expl A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
nvd
CVE-2022-41590P4MEDIUMCVSS 5.5v3.0.02022-12-20
CVE-2022-41590 [MEDIUM] CWE-287 CVE-2022-41590: Some smartphones have authentication-related (including session management) vulnerabilities as the s Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.
nvd
CVE-2024-51528P4MEDIUMCVSS 5.5v3.0.0v3.1.0+2 more2024-11-05
CVE-2024-51528 [MEDIUM] CWE-532 CVE-2024-51528: Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitati Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-51530P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-11-05
CVE-2024-51530 [MEDIUM] CWE-20 CVE-2024-51530: LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerabi LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-42034P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-08-08
CVE-2024-42034 [MEDIUM] CWE-840 CVE-2024-42034: LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerab LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-8298P4MEDIUMCVSS 5.5v4.0.0v4.2.02024-09-04
CVE-2024-8298 [MEDIUM] CWE-701 CVE-2024-8298: Memory request vulnerability in the memory management module Impact: Successful exploitation of this Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-36501P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-06-14
CVE-2024-36501 [MEDIUM] CWE-787 CVE-2024-36501: Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulne Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.
nvd
CVE-2024-42032P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-08-08
CVE-2024-42032 [MEDIUM] CWE-285 CVE-2024-42032: Access permission verification vulnerability in the Contacts module Impact: Successful exploitation Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-39670P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-07-25
CVE-2024-39670 [MEDIUM] CWE-264 CVE-2024-39670: Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploit Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-58252P4MEDIUMCVSS 5.5v5.0.02025-05-06
CVE-2024-58252 [MEDIUM] CWE-200 CVE-2024-58252: Vulnerability of insufficient information protection in the media library module Impact: Successful Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-36499P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-06-14
CVE-2024-36499 [MEDIUM] CWE-269 CVE-2024-36499: Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-24919P4MEDIUMCVSS 5.5v4.0.0v4.2.0+2 more2026-02-06
CVE-2026-24919 [MEDIUM] CWE-787 CVE-2026-24919: Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnera Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54615P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54615 [MEDIUM] CWE-200 CVE-2025-54615: Vulnerability of insufficient information protection in the media library module. Impact: Successful Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-54611P4MEDIUMCVSS 5.5v2.0.0v2.1.0+6 more2025-08-06
CVE-2025-54611 [MEDIUM] CWE-840 CVE-2025-54611: EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-24931P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-02-06
CVE-2026-24931 [MEDIUM] CWE-264 CVE-2026-24931: Vulnerability of improper criterion security check in the card module. Impact: Successful exploitati Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd