CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-58557MEDIUM | Generated title:Huawei HarmonyOS Expedition Mode Design Defect Affecting AvailabilityDesign defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability. CWE-701Jul 15, 2026 | CVSS4.8v3.1 | EPSS0.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41979MEDIUM | Generated title:HarmonyOS Print Module Permission Control VulnerabilityPermission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect integrity and confidentiality. CWE-701Jun 9, 2026 | CVSS5.5v3.1 | EPSS0.075% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41975MEDIUM | Generated title:HarmonyOS Network Management Module Permission Management VulnerabilityPermission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect service integrity. CWE-701Jun 9, 2026 | CVSS6.3v3.1 | EPSS0.067% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-57962MEDIUM | Vulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this vulnerability may affect availability. CWE-701Feb 6, 2025 | CVSS6.1v3.1 | EPSS0.188% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-52954MEDIUM | Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability. | CVSS4.4v3.1 | EPSS0.151% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8298MEDIUM | Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-701Sep 4, 2024 | CVSS6.2v3.1 | EPSS0.112% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42030MEDIUM | Access permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-701Aug 8, 2024 | CVSS6.2v3.1 | EPSS0.122% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6791MEDIUM | PAN-OS: Plaintext Disclosure of External System Integration CredentialsA credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface. | CVSS4.9v3.1 | EPSS0.624% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-46895CRITICAL | Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop. CWE-701Aug 13, 2023 | CVSS9.1v3.1 | EPSS0.388% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-48518MEDIUM | Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance. | CVSS5.5v3.1 | EPSS0.131% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-48517HIGH | Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability. CWE-701Jul 6, 2023 | CVSS7.5v3.1 | EPSS0.447% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-46892HIGH | Encryption bypass vulnerability in Maintenance mode. Successful exploitation of this vulnerability may affect service confidentiality. CWE-701Jul 6, 2023 | CVSS7.5v3.1 | EPSS0.272% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |