cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2021-22400,https://securityvulnerability.io/vulnerability/CVE-2021-22400,Input Validation Flaw in Huawei Smartphones,"Huawei smartphones are susceptible to an input validation vulnerability due to inadequate parameter checks. This weakness permits an attacker to deceive users into installing malicious applications. Once installed, these apps can alter critical system parameters, potentially causing significant disruptions such as system crashes. Users of affected models should remain vigilant and update their devices to mitigate the risks associated with this vulnerability. For more details, refer to Huawei's security advisory.",Huawei,Oxfords-an00a,5.5,MEDIUM,0.0005499999970197678,false,,false,false,false,,,false,false,,2021-08-03T13:18:05.000Z,0 CVE-2021-22440,https://securityvulnerability.io/vulnerability/CVE-2021-22440,,"There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename. Affected product versions include:HUAWEI Mate 20 9.0.0.195(C01E195R2P1), 9.1.0.139(C00E133R3P1);HUAWEI Mate 20 Pro 9.0.0.187(C432E10R1P16), 9.0.0.188(C185E10R2P1), 9.0.0.245(C10E10R2P1), 9.0.0.266(C432E10R1P16), 9.0.0.267(C636E10R2P1), 9.0.0.268(C635E12R1P16), 9.0.0.278(C185E10R2P1); Hima-L29C 9.0.0.105(C10E9R1P16), 9.0.0.105(C185E9R1P16), 9.0.0.105(C636E9R1P16); Laya-AL00EP 9.1.0.139(C786E133R3P1); OxfordS-AN00A 10.1.0.223(C00E210R5P1); Tony-AL00B 9.1.0.257(C00E222R2P1).",Huawei,Huawei Mate 20;huawei Mate 20 Pro;hima-l29c;laya-al00ep;oxfords-an00a;tony-al00b,4.6,MEDIUM,0.0006900000153109431,false,,false,false,false,,,false,false,,2021-07-13T11:42:33.000Z,0 CVE-2020-9235,https://securityvulnerability.io/vulnerability/CVE-2020-9235,,"Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.212(C432E10R3P4),Versions earlier than 10.1.0.213(C636E3R4P3),Versions earlier than 10.1.0.214(C10E5R4P3),Versions earlier than 10.1.0.214(C185E3R3P3);Versions earlier than 10.1.0.212(C00E210R5P1);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C01E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R8P12);Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.225(C431E3R1P2),Versions earlier than 10.1.0.225(C432E3R1P2) contain an information vulnerability. A module has a design error that is lack of control of input. Attackers can exploit this vulnerability to obtain some information. This can lead to information leak.",Huawei,Honor 20 Pro;honor View 20;oxfords-an00a;princeton-al10b;princeton-al10d;princeton-tl10c;tony-al00b;yale-al00a;yale-l21a;yale-l61a,5.5,MEDIUM,0.0004400000034365803,false,,false,false,false,,,false,false,,2020-09-03T18:04:26.000Z,0 CVE-2020-1878,https://securityvulnerability.io/vulnerability/CVE-2020-1878,,"Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit this vulnerability to obtain some information by loading malicious application, leading to information leak.",Huawei,Oxfords-an00a,5.5,MEDIUM,0.0004400000034365803,false,,false,false,false,,,false,false,,2020-03-20T14:50:22.000Z,0