VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2025-58313
Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module.
Published 2025-09-05 · Analyzed
5.1EPSS 0.001
CVE-2025-66320
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-12-08 · Analyzed
5.1EPSS 0.001
CVE-2025-66321
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-12-08 · Analyzed
5.1EPSS 0.001
CVE-2025-66322
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-12-08 · Analyzed
5.1EPSS 0.001
CVE-2025-53178
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.
Published 2025-07-07 · Analyzed
4.8EPSS 0.001
CVE-2025-54651
Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-08-06 · Analyzed
4.8EPSS 0.001
CVE-2021-40015
There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vulnerability may affect kernel stability.
Published 2022-02-09 · Modified
4.7EPSS 0.001
CVE-2022-31758
The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-06-13 · Modified
4.7EPSS 0.001
CVE-2026-28543
Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-03-05 · Analyzed
4.7EPSS 0.001
CVE-2026-28550
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-03-05 · Analyzed
4.7EPSS 0.001
CVE-2026-28551
Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-03-05 · Analyzed
4.7EPSS 0.001
CVE-2026-34849
UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-04-13 · Analyzed
4.7EPSS 0.001
CVE-2021-22464
A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause system Soft Restart.
Published 2021-10-28 · Modified
4.6EPSS 0.002
CVE-2021-40006
Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.
Published 2022-01-07 · Modified
4.6EPSS 0.001
CVE-2025-54649
Vulnerability of using incompatible types to access resources in the location service. Impact: Successful exploitation of this vulnerability may cause some location information attributes to be incorrect.
Published 2025-08-06 · Analyzed
4.5EPSS 0.001
CVE-2025-54626
Pointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect function stability.
Published 2025-08-06 · Analyzed
4.4EPSS 0.001
CVE-2021-37073
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the detection result is tampered with.
Published 2021-12-07 · Modified
4.3EPSS 0.003
CVE-2023-52544
Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-04-08 · Analyzed
4.3EPSS 0.003
CVE-2023-52380
Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-02-18 · Analyzed
4.3EPSS 0.003
CVE-2023-44110
Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availability.
Published 2023-10-11 · Modified
4.3EPSS 0.002
CVE-2022-44548
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing.
Published 2022-11-09 · Modified
4.3EPSS 0.002
CVE-2023-52720
Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-05-11 · Analyzed
4.1EPSS 0.001
CVE-2026-34858
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-04-13 · Analyzed
4.1EPSS 0.001
CVE-2026-28540
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2026-03-05 · Analyzed
4.0EPSS 0.001
CVE-2024-5464
Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-06-14 · Modified
4.0EPSS 0.001
CVE-2024-58114
Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-06-06 · Analyzed
4.0EPSS 0.001
CVE-2024-58117
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
Published 2025-07-07 · Analyzed
4.0EPSS 0.001
CVE-2025-53171
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
Published 2025-07-07 · Analyzed
4.0EPSS 0.001
CVE-2025-53172
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
Published 2025-07-07 · Analyzed
4.0EPSS 0.001
CVE-2025-53174
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
Published 2025-07-07 · Analyzed
4.0EPSS 0.001
CVE-2025-53175
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
Published 2025-07-07 · Analyzed
4.0EPSS 0.001
CVE-2025-53177
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.
Published 2025-07-07 · Analyzed
3.9EPSS 0.001
CVE-2023-41306
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.
Published 2023-09-26 · Modified
3.7EPSS 0.004
CVE-2023-52371
Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.
Published 2024-02-18 · Analyzed
3.5EPSS 0.002
CVE-2022-41597
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
Published 2022-10-14 · Modified
3.4EPSS 0.002
CVE-2022-41592
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
Published 2022-10-14 · Modified
3.4EPSS 0.002
CVE-2022-41593
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
Published 2022-10-14 · Modified
3.4EPSS 0.002
CVE-2022-41594
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
Published 2022-10-14 · Modified
3.4EPSS 0.002
CVE-2022-41595
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
Published 2022-10-14 · Modified
3.4EPSS 0.002
CVE-2022-41598
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
Published 2022-10-14 · Modified
3.4EPSS 0.002
← Prev26 / 27Next →