Vulnerabilities
165 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-41432 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2025-27128 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2025-27131 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. NVD description · AI analysis pending | 5.5 group max | <1% |
| — | ||
| CVE-2025-27132 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2025-22851 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2025-24309 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. NVD description · AI analysis pending | 7.8 group max | <1% |
| — |