VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2024-36503
Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-06-14 · Modified
7.3EPSS 0.001
CVE-2025-54606
Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2025-08-06 · Analyzed
7.3EPSS 0.001
CVE-2025-54611
EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-08-06 · Analyzed
7.3EPSS 0.001
CVE-2025-58298
Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.
Published 2025-10-11 · Analyzed
7.3EPSS 0.001
CVE-2026-24925
Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
7.3EPSS 0.001
CVE-2025-58308
Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2025-11-28 · Analyzed
7.3EPSS 0.001
CVE-2025-58316
DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-11-28 · Analyzed
7.3EPSS 0.001
CVE-2021-40055
There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity.
Published 2022-03-07 · Modified
7.1EPSS 0.005
CVE-2021-37085
There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.
Published 2021-12-07 · Modified
7.1EPSS 0.005
CVE-2023-52719
Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-05-11 · Analyzed
7.1EPSS 0.002
CVE-2021-22469
A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.
Published 2021-10-28 · Modified
7.1EPSS 0.002
CVE-2021-22326
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.
Published 2021-06-30 · Modified
7.1EPSS 0.002
CVE-2025-48909
Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-06-06 · Analyzed
7.1EPSS 0.002
CVE-2022-41577
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.
Published 2022-10-14 · Modified
7.1EPSS 0.001
CVE-2026-24915
Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-02-06 · Analyzed
7.1EPSS 0.001
CVE-2024-39673
Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-07-25 · Modified
7.1EPSS 0.001
CVE-2024-54099
File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2024-12-12 · Modified
7.1EPSS 0.001
CVE-2026-34859
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-04-13 · Analyzed
7.1EPSS 0.001
CVE-2026-28548
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2026-03-05 · Analyzed
7.1EPSS 0.001
CVE-2024-42033
Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2024-08-08 · Modified
7.1EPSS 0.001
CVE-2025-46589
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-05-06 · Analyzed
7.1EPSS 0.001
CVE-2026-34854
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-04-13 · Analyzed
7.1EPSS 0.001
CVE-2025-58314
Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2025-11-28 · Analyzed
7.1EPSS 0.001
CVE-2025-58309
Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2025-11-28 · Analyzed
7.1EPSS 0.001
CVE-2025-64315
Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.
Published 2025-11-28 · Analyzed
7.1EPSS 0.001
CVE-2026-24921
Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-02-06 · Analyzed
7.1EPSS 0.001
CVE-2025-58311
UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2025-11-28 · Analyzed
7.1EPSS 0.001
CVE-2025-66327
Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-12-08 · Analyzed
7.1EPSS 0.001
CVE-2026-24922
Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
6.9EPSS 0.001
CVE-2024-32999
Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-05-11 · Analyzed
6.8EPSS 0.002
CVE-2025-54632
Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect service integrity.
Published 2025-08-06 · Analyzed
6.8EPSS 0.001
CVE-2026-24918
Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
6.8EPSS 0.001
CVE-2025-31171
File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-04-07 · Analyzed
6.8EPSS 0.001
CVE-2024-56453
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-01-08 · Analyzed
6.8EPSS 0.001
CVE-2024-56456
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-01-08 · Analyzed
6.8EPSS 0.001
CVE-2024-36499
Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-06-14 · Modified
6.8EPSS 0.001
CVE-2026-34864
Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-04-13 · Analyzed
6.8EPSS 0.001
CVE-2026-28547
Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-03-05 · Analyzed
6.8EPSS 0.001
CVE-2025-27521
Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-03-04 · Analyzed
6.8EPSS 0.001
CVE-2025-58276
Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-09-05 · Analyzed
6.8EPSS 0.001
← Prev18 / 27Next →