VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2022-48290
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity.
Published 2023-02-09 · Modified
9.1EPSS 0.004
CVE-2023-5801
Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2023-11-08 · Modified
9.1EPSS 0.004
CVE-2022-48348
The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and integrity.
Published 2023-03-27 · Modified
9.1EPSS 0.004
CVE-2023-52369
Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.
Published 2024-02-18 · Modified
9.1EPSS 0.004
CVE-2023-39407
The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
Published 2023-09-25 · Modified
9.1EPSS 0.004
CVE-2023-44118
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2023-10-11 · Modified
9.1EPSS 0.004
CVE-2023-39385
Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access.
Published 2023-08-13 · Modified
9.1EPSS 0.004
CVE-2022-48312
The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.
Published 2023-04-16 · Modified
9.1EPSS 0.004
CVE-2023-44107
Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.
Published 2023-10-11 · Modified
9.1EPSS 0.004
CVE-2023-52101
Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.
Published 2024-01-16 · Modified
9.1EPSS 0.004
CVE-2023-39403
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Published 2023-08-13 · Modified
9.1EPSS 0.004
CVE-2023-39399
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Published 2023-08-13 · Modified
9.1EPSS 0.004
CVE-2023-39398
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Published 2023-08-13 · Modified
9.1EPSS 0.004
CVE-2023-41296
Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.
Published 2023-09-25 · Modified
9.1EPSS 0.004
CVE-2024-30415
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-04-07 · Analyzed
9.1EPSS 0.004
CVE-2023-52953
Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-01-08 · Analyzed
9.1EPSS 0.003
CVE-2023-52106
Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
Published 2024-01-16 · Modified
9.1EPSS 0.003
CVE-2023-52538
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-04-08 · Modified
9.1EPSS 0.003
CVE-2024-57958
Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2025-02-06 · Analyzed
9.1EPSS 0.002
CVE-2024-58126
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2024-58127
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2024-58125
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2025-31170
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2024-58124
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2021-40000
The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.
Published 2022-01-07 · Modified
8.8EPSS 0.004
CVE-2021-40002
The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.
Published 2022-01-07 · Modified
8.8EPSS 0.004
CVE-2025-48906
Authentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-06-06 · Analyzed
8.8EPSS 0.002
CVE-2025-54627
Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-08-06 · Analyzed
8.8EPSS 0.002
CVE-2025-31173
Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-04-07 · Analyzed
8.8EPSS 0.001
CVE-2024-42038
Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Published 2024-08-08 · Modified
8.8EPSS 0.001
CVE-2021-37086
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sandbox.
Published 2021-12-07 · Modified
8.6EPSS 0.006
CVE-2024-58045
Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-03-04 · Analyzed
8.6EPSS 0.001
CVE-2024-54098
Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.
Published 2024-12-12 · Analyzed
8.5EPSS 0.002
CVE-2025-31175
Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.
Published 2025-04-07 · Analyzed
8.4EPSS 0.002
CVE-2021-22376
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.
Published 2021-06-30 · Modified
8.4EPSS 0.002
CVE-2024-32997
Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-05-11 · Analyzed
8.4EPSS 0.001
CVE-2024-42035
Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.
Published 2024-08-08 · Modified
8.4EPSS 0.001
CVE-2025-54653
Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization file module.
Published 2025-08-06 · Analyzed
8.4EPSS 0.001
CVE-2025-54652
Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization module.
Published 2025-08-06 · Analyzed
8.4EPSS 0.001
CVE-2024-39672
Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
Published 2024-07-25 · Modified
8.4EPSS 0.001
← Prev4 / 27Next →