Harmonyos

Vendor:

First CVE: Mar 2, 2021 · Active for 5 years

1,050
Total CVEs
More Total CVEs than 100% of tracked products
175.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Harmonyos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2021
5 years ago
Most Recent CVE
Apr 13, 2026
103 days ago

CVE Severity & Scoring

Harmonyos1,050 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local343 (32.7%)
Network674 (64.2%)
Unknown0 (0.0%)
Physical2 (0.2%)
Adjacent Network31 (3.0%)
Attack Complexity
Low989 (94.2%)
High61 (5.8%)
Unknown0 (0.0%)
User Interaction
None1,036 (98.7%)
Unknown0 (0.0%)
Required14 (1.3%)
Privileges Required
Low314 (29.9%)
High15 (1.4%)
None721 (68.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (1050 CVEs).

1,050 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.
Sep 16, 20229.832NONO
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
Dec 20, 20229.831NONO
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
Dec 20, 20229.831NONO
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
Dec 20, 20229.831NONO
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
Dec 20, 20229.831NONO
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
Dec 20, 20229.831NONO
The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.
Dec 20, 20229.831NONO
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
Dec 20, 20229.831NONO
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Nov 9, 20229.831NONO
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
Nov 9, 20229.831NONO

Exploit Exposure

Signals from CVEs in this product scope (1050 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (1050 CVEs).

Media Mentions

Signals from CVEs in this product scope (1050 CVEs).

Top CNAs Publishing CVEs For Harmonyos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.0.0825.60.1%00
5.1.155.50.1%00
5.1.01265.50.1%00
5.0.2176.30.1%00
5.0.11105.60.1%00
5.0.01006.60.2%00
4.3.1226.00.1%00
4.3.0376.50.1%00
4.2.01086.30.1%00
4.0.02666.80.3%00
3.1.02657.00.3%00
3.0.03187.10.3%00
2.1.01797.00.3%00
2.1537.70.4%00
2.0.1917.30.4%00
2.0.02107.10.3%00
2.02717.40.5%00