CVE Tools

Openharmony

177 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Openharmony, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Openharmony CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Openharmony CVEs per month
MonthCVEs
2024-105
2024-114
2024-123
2025-013
2025-023
2025-0326
2025-047
2025-056
2025-0611
2025-070
2025-0810
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-037
2026-040
2026-0510
2026-060
2026-070
2026-080
2026-090

Severity

How the 177 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High3520%
  • Medium6637%
  • Low7643%

Latest CVEs

The 15 most recently published vulnerabilities affecting Openharmony.

  1. CVE-2026-33565kernel_linux_common_modules has a Race Condition vulnerability3.3
  2. CVE-2026-28733filemanagement_storage_service has an use after free vulnerability6.5
  3. CVE-2026-27766multimedia_audio_framework has a Race Condition vulnerability5.5
  4. CVE-2026-25850filemanagement_storage_service has an improper preservation of permissions vulnerability5.5
  5. CVE-2026-25781kernel_liteos_a has an out-of-bounds write vulnerability8.4
  6. CVE-2026-28751filemanagement_storage_service has an improper input validation vulnerability3.3
  7. CVE-2026-27781kernel_liteos_a has an integer overflow vulnerability3.3
  8. CVE-2026-27648web_webview has an out-of-bounds write vulnerability8.8
  9. CVE-2026-25110Sensors_medical_sensor has a NULL pointer dereference vulnerability3.3
  10. CVE-2026-24792web_webview has a Race Condition vulnerability8.1
  11. CVE-2025-6969ability_ability_runtime an improper input validation vulnerability5.0
  12. CVE-2025-26474communication_ipc an improper input validation vulnerability3.3
  13. CVE-2025-52458arkcompiler_ets_runtime has an out-of-bounds write vulnerability5.5
  14. CVE-2025-41432arkcompiler_ets_runtime has an out-of-bounds write vulnerability5.5
  15. CVE-2025-25277arkcompiler_ets_runtime has a type confusion vulnerability6.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store