Browse all 4 CVE security advisories affecting Harmonic Design. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Harmonic Design develops network security solutions focusing on threat detection and mitigation. Historically, their products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from improper input validation and access control weaknesses. While no major public security incidents have been widely documented, their CVE history suggests consistent vulnerabilities in web interfaces and authentication mechanisms. The company's security posture appears to prioritize functionality over robustness, with multiple instances of unauthenticated RCE and session management issues across different product versions.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-24544 | WordPress HD Quiz plugin <= 2.0.9 - Broken Access Control vulnerability — HD QuizCWE-862 | 4.3 | Medium | 2026-01-23 |
| CVE-2025-68912 | WordPress HDForms plugin <= 1.6.1 - Arbitrary File Deletion vulnerability — HDFormsCWE-22 | 8.6 | High | 2026-01-22 |
| CVE-2024-49689 | WordPress HD Quiz – Save Results Light plugin <= 0.5 - Broken Access Control vulnerability — HD Quiz – Save Results LightCWE-862 | 5.4 | Medium | 2024-11-19 |
| CVE-2024-22161 | WordPress HD Quiz Plugin <= 1.8.11 is vulnerable to Cross Site Scripting (XSS) — HD QuizCWE-79 | 5.9 | Medium | 2024-01-31 |
This page lists every published CVE security advisory associated with Harmonic Design. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.