VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2024-56452
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-01-08 · Analyzed
5.5EPSS 0.001
CVE-2022-48518
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.
Published 2023-07-06 · Modified
5.5EPSS 0.001
CVE-2022-41590
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.
Published 2022-12-20 · Modified
5.5EPSS 0.001
CVE-2026-24914
Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
5.5EPSS 0.001
CVE-2026-28541
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-03-05 · Analyzed
5.5EPSS 0.001
CVE-2024-51528
Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-11-05 · Analyzed
5.5EPSS 0.001
CVE-2024-51524
Permission control vulnerability in the Wi-Fi module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-11-05 · Analyzed
5.5EPSS 0.001
CVE-2024-45444
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-09-04 · Analyzed
5.5EPSS 0.001
CVE-2024-51517
Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2024-11-05 · Analyzed
5.5EPSS 0.001
CVE-2024-51520
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2024-11-05 · Analyzed
5.5EPSS 0.001
CVE-2024-45449
Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-09-04 · Analyzed
5.5EPSS 0.001
CVE-2024-51513
Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption.
Published 2024-11-05 · Modified
5.5EPSS 0.001
CVE-2024-42032
Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-08-08 · Modified
5.5EPSS 0.001
CVE-2024-54096
Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.
Published 2024-12-12 · Analyzed
5.5EPSS 0.001
CVE-2024-45445
Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-09-04 · Analyzed
5.5EPSS 0.001
CVE-2024-51514
Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-11-05 · Analyzed
5.5EPSS 0.001
CVE-2024-51519
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2024-11-05 · Analyzed
5.5EPSS 0.001
CVE-2025-58290
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
Published 2025-10-11 · Analyzed
5.5EPSS 0.001
CVE-2024-45446
Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-09-04 · Analyzed
5.5EPSS 0.001
CVE-2025-58291
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
Published 2025-10-11 · Analyzed
5.5EPSS 0.001
CVE-2025-58292
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
Published 2025-10-11 · Analyzed
5.5EPSS 0.001
CVE-2025-58286
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
Published 2025-10-11 · Analyzed
5.5EPSS 0.001
CVE-2025-54620
Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-08-06 · Analyzed
5.5EPSS 0.001
CVE-2025-66319
Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.
Published 2026-03-05 · Analyzed
5.5EPSS 0.001
CVE-2023-7271
Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-07-25 · Modified
5.5EPSS 0.001
CVE-2024-51527
Permission control vulnerability in the Gallery app Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-11-05 · Analyzed
5.5EPSS 0.001
CVE-2024-51529
Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.
Published 2024-11-05 · Analyzed
5.5EPSS 0.001
CVE-2021-22460
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2024-56454
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-01-08 · Analyzed
5.5EPSS 0.001
CVE-2024-56455
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-01-08 · Analyzed
5.5EPSS 0.001
CVE-2025-46593
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-05-06 · Analyzed
5.5EPSS 0.001
CVE-2026-24927
Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
5.5EPSS 0.001
CVE-2025-46592
Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-05-06 · Analyzed
5.5EPSS 0.001
CVE-2024-47290
Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2024-09-27 · Analyzed
5.5EPSS 0.001
CVE-2025-54640
ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.
Published 2025-08-06 · Analyzed
5.5EPSS 0.001
CVE-2025-54639
ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.
Published 2025-08-06 · Analyzed
5.5EPSS 0.001
CVE-2024-58047
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-03-04 · Analyzed
5.5EPSS 0.001
CVE-2024-58049
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-03-04 · Analyzed
5.5EPSS 0.001
CVE-2021-22419
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.
Published 2021-08-03 · Modified
5.5EPSS 0.001
CVE-2026-28537
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-03-05 · Analyzed
5.5EPSS 0.001
← Prev23 / 27Next →