Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 46 of 56
CVE-2026-41979P4MEDIUMCVSS 5.5v6.1.0v6.0.02026-06-09
CVE-2026-41979 [MEDIUM] CWE-701 CVE-2026-41979: Permission control vulnerability in the print module. Impact: Successful exploitation of this vulner
Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect integrity and confidentiality.
nvd
CVE-2026-28547P4MEDIUMCVSS 5.5v6.0.02026-03-05
CVE-2026-28547 [MEDIUM] CWE-824 CVE-2026-28547: Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitatio
Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-39980P4MEDIUMCVSS 5.3v2.02022-01-03
CVE-2021-39980 [MEDIUM] CWE-200 CVE-2021-39980: Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could lead to sensitive information disclosure.
nvd
CVE-2022-47974P4MEDIUMCVSS 6.5fixed in 2.0v2.0+2 more2023-01-06
CVE-2022-47974 [MEDIUM] CWE-287 CVE-2022-47974: The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation
The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth process to restart.
nvd
CVE-2023-7265P4MEDIUMCVSS 6.2v2.0.0v2.1.0+4 more2024-08-08
CVE-2023-7265 [MEDIUM] CWE-264 CVE-2023-7265: Permission verification vulnerability in the lock screen module Impact: Successful exploitation of t
Permission verification vulnerability in the lock screen module
Impact: Successful exploitation of this vulnerability may affect availability
nvd
CVE-2025-48907P4MEDIUMCVSS 6.2v5.0.02025-06-06
CVE-2025-48907 [MEDIUM] CWE-248 CVE-2025-48907: Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerabilit
Deserialization vulnerability in the IPC module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-48904P4MEDIUMCVSS 6.2v5.0.02025-06-06
CVE-2025-48904 [MEDIUM] CWE-288 CVE-2025-48904: Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitati
Vulnerability that cards can call unauthorized APIs in the FRS process
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-32999P4MEDIUMCVSS 5.5v2.0.0v2.1.0+3 more2024-05-14
CVE-2024-32999 [MEDIUM] CWE-840 CVE-2024-32999: Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerabili
Cracking vulnerability in the OS security module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-49248P4MEDIUMCVSS 5.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49248 [MEDIUM] CWE-20 CVE-2023-49248: Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulne
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
nvd
CVE-2021-22478P4MEDIUMCVSS 5.5fixed in 2.0v2.02022-02-25
CVE-2021-22478 [MEDIUM] CWE-416 CVE-2021-22478: The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this
The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may lead to information leakage.
nvd
CVE-2024-32998P4MEDIUMCVSS 5.5v2.0.0v2.1.0+3 more2024-05-14
CVE-2024-32998 [MEDIUM] CWE-824 CVE-2024-32998: NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulner
NULL pointer access vulnerability in the clock module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2021-40045P4MEDIUMCVSS 5.5fixed in 2.0v4.0.02022-02-09
CVE-2021-40045 [MEDIUM] CWE-347 CVE-2021-40045: There is a vulnerability of signature verification mechanism failure in system upgrade through recov
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-32993P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-05-14
CVE-2024-32993 [MEDIUM] CWE-362 CVE-2024-32993: Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vuln
Out-of-bounds access vulnerability in the memory module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-48518P4MEDIUMCVSS 5.5v2.0.0v2.0.12023-07-06
CVE-2022-48518 [MEDIUM] CWE-701 CVE-2022-48518: Vulnerability of signature verification in the iaware system being initialized later than the time w
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.
nvd
CVE-2024-4046P4MEDIUMCVSS 5.5v3.1.0v4.0.0+1 more2024-05-14
CVE-2024-4046 [MEDIUM] CWE-840 CVE-2024-4046: Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerabili
Cracking vulnerability in the OS security module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-45446P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-09-04
CVE-2024-45446 [MEDIUM] CWE-20 CVE-2024-45446: Access permission verification vulnerability in the camera driver module Impact: Successful exploita
Access permission verification vulnerability in the camera driver module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-51516P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51516 [MEDIUM] CWE-862 CVE-2024-51516: Permission control vulnerability in the ability module Impact: Successful exploitation of this vulne
Permission control vulnerability in the ability module
Impact: Successful exploitation of this vulnerability may cause features to function abnormally.
nvd
CVE-2024-47290P4MEDIUMCVSS 5.5v2.0.0v2.1.0+3 more2024-09-27
CVE-2024-47290 [MEDIUM] CWE-476 CVE-2024-47290: Input validation vulnerability in the USB service module Impact: Successful exploitation of this vul
Input validation vulnerability in the USB service module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54616P4MEDIUMCVSS 5.5v5.1.02025-08-06
CVE-2025-54616 [MEDIUM] CWE-787 CVE-2025-54616: Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of
Out-of-bounds array access vulnerability in the ArkUI framework.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58044P4MEDIUMCVSS 5.5v2.0.0v2.1.0+5 more2025-03-04
CVE-2024-58044 [MEDIUM] CWE-20 CVE-2024-58044: Permission verification bypass vulnerability in the notification module Impact: Successful exploitat
Permission verification bypass vulnerability in the notification module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd