4
CVE-2026-28540 - Out‑of‑Bounds Character Read in Bluetooth on Huawei HarmonyOS
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
6.2
CVE-2026-28539 - Certificate Management Data Processing Vulnerability Threatening Service Confidentiality
Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
5.9
CVE-2026-28538 - Path Traversal in HarmonyOS Certificate Management Leading to Availability Issues
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.
3.3
CVE-2025-66319 -
Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.
6.5
CVE-2026-28552 - IMS Module Out‑of‑Bounds Write Causing Availability Disruption
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.
4
CVE-2026-28550 - Race Condition in HarmonyOS Security Control Module Leading to Availability Impact
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.
5.9
CVE-2026-28545 - Race Condition in HarmonyOS Printing Module Causing Availability Impact
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
6.2
CVE-2026-28544 - Race condition in HarmonyOS printing module causing potential denial of service
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
8.1
CVE-2026-1321 - Membership Plugin – Restrict Content <= 3.2.20 - Unauthenticated Privilege Escalation via 'rcp_leve…
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that …
6.5
CVE-2026-2893 - Page and Post Clone <= 6.3 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter
The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_clone() function in all versions up to, and including, 6.3. This is due to insufficient escaping on the user-supplied meta_key value and insufficient preparation on the existing S…