Openharmony
Vendor:
First CVE: Sep 9, 2022 · Active for 3 years
156
Total CVEs
More Total CVEs than 99% of tracked products
31.2
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openharmony over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2022
3 years ago
Most Recent CVE
Mar 16, 2026
130 days ago
CVE Severity & Scoring
Openharmony156 CVEs
56%
37%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local144 (92.3%)
Network9 (5.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (1.9%)
Attack Complexity
Low152 (97.4%)
High4 (2.6%)
Unknown0 (0.0%)
User Interaction
None155 (99.4%)
Unknown0 (0.0%)
Required1 (0.6%)
Privileges Required
Low142 (91.0%)
High1 (0.6%)
None13 (8.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (156 CVEs).
156 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-36260CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | Jul 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-27128HIGH in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | Aug 11, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-24298HIGH in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | Aug 11, 2025 | 7.8 | 26 | NO | NO |
CVE-2024-37185CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-37077CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-37030CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-36243CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2022-43662HIGH Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kern | Jan 9, 2023 | 7.8 | 26 | NO | NO |
CVE-2025-27577HIGH in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. | Aug 11, 2025 | 7.0 | 25 | NO | NO |
CVE-2024-22098HIGH in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free. | Apr 2, 2024 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (156 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (156 CVEs).
Media Mentions
Signals from CVEs in this product scope (156 CVEs).
Top CNAs Publishing CVEs For Openharmony
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.1.0 | 4 | 7.0 | 0.2% | 0 | 0 |
| 5.0.3 | 6 | 6.3 | 0.2% | 0 | 0 |
| 4.0.1 | 2 | 5.5 | 0.1% | 0 | 0 |
| 4.0 | 9 | 6.3 | 0.2% | 0 | 0 |