OpenHarmony
First CVE: Sep 9, 2022Active for: 4 years
177
CVEs Published
More CVEs Published than 78% of tracked CNAs
35.4
Avg CVEs / Year
More Avg CVEs / Year than 79% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 21% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by OpenHarmony as a CNA, 10.2% affect products that OpenHarmony develops as a vendor.
10.2%
89.8%
Self-reported: 18Third-party: 159
Of all the CVEs published that affect products developed by OpenHarmony, 100.0% are self-published by OpenHarmony as a CNA.
100.0%
Self-published: 18Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by OpenHarmony over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2022
3 years ago
Most Recent CVE
May 19, 2026
66 days ago
Top CVEs
All CVEs published by OpenHarmony as a CNA, regardless of affected vendor or product.
177 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27648HIGH in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. | May 19, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-25781HIGH in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered. | May 19, 2026 | 8.4 | 32 | NO | NO |
CVE-2026-24792HIGH in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. | May 19, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-28733MEDIUM in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution. | May 19, 2026 | 6.5 | 27 | NO | NO |
CVE-2024-36260CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | Jul 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-42463HIGH OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch a | Oct 14, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-38700HIGH OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service. | Sep 9, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-27128HIGH in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | Aug 11, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-24298HIGH in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | Aug 11, 2025 | 7.8 | 26 | NO | NO |
CVE-2024-37185CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA177 CVEs
54%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local159 (89.8%)
Network12 (6.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network6 (3.4%)
Attack Complexity
Low172 (97.2%)
High5 (2.8%)
Unknown0 (0.0%)
User Interaction
None176 (99.4%)
Unknown0 (0.0%)
Required1 (0.6%)
Privileges Required
Low159 (89.8%)
High1 (0.6%)
None17 (9.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (177 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by OpenHarmony as a CNA.
Media Mentions
Media articles that mention a CVE ID published by OpenHarmony as a CNA — matched by CVE ID, not by organization name.