Vulnerabilities (CVE)

Total 404108 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-28551 1 Huawei 1 Harmonyos 2026-06-17 N/A 4.7 MEDIUM
Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28550 1 Huawei 1 Harmonyos 2026-06-17 N/A 4.0 MEDIUM
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28549 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.6 MEDIUM
Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28548 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 7.1 HIGH
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-28547 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.8 MEDIUM
Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28546 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.9 MEDIUM
Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28545 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.9 MEDIUM
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28544 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28543 1 Huawei 1 Harmonyos 2026-06-17 N/A 4.4 MEDIUM
Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28542 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 7.3 HIGH
Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28541 1 Huawei 1 Harmonyos 2026-06-17 N/A 4.0 MEDIUM
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28540 1 Huawei 1 Harmonyos 2026-06-17 N/A 4.0 MEDIUM
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-28539 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-28538 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.9 MEDIUM
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28537 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.1 MEDIUM
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28536 1 Huawei 1 Harmonyos 2026-06-17 N/A 9.6 CRITICAL
Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
CVE-2026-28532 1 Frrouting 1 Frrouting 2026-06-17 N/A 6.5 MEDIUM
FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement continues unchecked. Attackers with an established OSPF adjacency can send a crafted LS Update packet with a malicious Type 10 or Type 11 Opaque LSA to trigger out-of-bounds memory reads and crash all affected routers in the OSPF area or autonomous system.
CVE-2026-28522 1 Tuya 1 Arduino-tuyaopen 2026-06-17 N/A 6.5 MEDIUM
arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets that trigger a null pointer dereference, resulting in a denial-of-service condition.
CVE-2026-28521 1 Tuya 1 Arduino-tuyaopen 2026-06-17 N/A 7.7 HIGH
arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP event data to victim devices, causing out-of-bounds memory access that may result in information disclosure or a denial-of-service condition.
CVE-2026-28520 1 Tuya 1 Arduino-tuyaopen 2026-06-17 N/A 8.4 HIGH
arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can exploit the overflow to execute arbitrary code on the affected embedded device.