5
CVE-2025-6969 - ability_ability_runtime an improper input validation vulnerability
in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
3.3
CVE-2025-26474 - communication_ipc an improper input validation vulnerability
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can be exploited only in restricted scenarios.
5.5
CVE-2025-52458 - arkcompiler_ets_runtime has an out-of-bounds write vulnerability
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
5.5
CVE-2025-41432 - arkcompiler_ets_runtime has an out-of-bounds write vulnerability
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
6.3
CVE-2025-25277 - arkcompiler_ets_runtime has a type confusion vulnerability
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.
6.5
CVE-2025-12736 - multimedia_audio_standard has an insecure storage of sensitive information vulnerability
in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource.
3.3
CVE-2026-0639 - liteos_a has a missing release of memory vulnerability
in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
2.9
CVE-2026-32778 - libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
6.9
CVE-2026-4223 - itsourcecode Payroll Management System manage_employee.php sql injection
A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /manage_employee.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might beโฆ
4
CVE-2026-32777 - libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.