VYPR
Vendor

Honojs

Products
28
CVEs
109
Across products
139
Status
Private

Products

28

Recent CVEs

109
View all 109 CVEs →
  • CVE-2020-9144CriJan 13, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a heap overflow vulnerability in some Huawei smartphone, attackers can exploit this vulnerability to cause heap overflows due to improper restriction of operations within the bounds of a memory buffer.

  • CVE-2023-51434CriDec 29, 2023
    risk 0.60cvss 9.3epss 0.00

    Some Honor products are affected by buffer overflow vulnerability, successful exploitation could cause code execution.

  • CVE-2025-46014HigJun 30, 2025
    risk 0.57cvss 8.8epss 0.00

    Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.

  • CVE-2019-5218HigNov 29, 2019
    risk 0.57cvss 8.8epss 0.00

    There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.

  • CVE-2025-2188HigApr 17, 2025
    risk 0.53cvss 8.1epss 0.00

    There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity.

  • CVE-2025-1532HigApr 17, 2025
    risk 0.53cvss 8.1epss 0.00

    Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity.

  • CVE-2026-31368HigApr 21, 2026
    risk 0.51cvss 7.8epss 0.00

    AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.

  • CVE-2023-23436HigDec 29, 2023
    risk 0.47cvss 7.3epss 0.00

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file

  • CVE-2023-23432HigDec 29, 2023
    risk 0.47cvss 7.3epss 0.00

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

  • CVE-2023-23431HigDec 29, 2023
    risk 0.47cvss 7.3epss 0.00

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

  • CVE-2026-27700HigFeb 25, 2026
    risk 0.46cvss 8.2epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load Balancer (ALB), the `getConnInfo()` function incorrectly selected the first value…

  • CVE-2026-22818HigJan 13, 2026
    risk 0.46cvss 8.2epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did…

  • CVE-2026-22817HigJan 13, 2026
    risk 0.46cvss 8.2epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not…

  • CVE-2025-62610HigOct 22, 2025
    risk 0.46cvss 8.1epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an…

  • CVE-2023-51435HigDec 29, 2023
    risk 0.46cvss 7.1epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

  • CVE-2023-51431HigDec 29, 2023
    risk 0.46cvss 7.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2023-23426MedDec 29, 2023
    risk 0.43cvss 6.6epss 0.00

    Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure.

  • CVE-2026-39408HigApr 8, 2026
    risk 0.42cvss 7.5epss 0.01

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via…

  • CVE-2026-29087HigMar 6, 2026
    risk 0.42cvss 7.5epss 0.00

    @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static…

  • CVE-2026-29045HigMar 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to…