Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.6 CVE-2026-54317 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist… Home Assistant 2026.6.0+ Fix from $1,9502026-06-23 HIGH 7.1 CVE-2026-54318 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager Broadc… Home Assistant Companion 2026.5.3+ Fix from $1,9502026-06-23 MEDIUM 5.4 CVE-2026-33045 Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 20… Home Assistant 2026.1.0+ Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2026-33044 Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 20… Home Assistant 2026.1.0+ Fix from $1,6002026-03-27 MEDIUM 5.4 CVE-2023-41893 Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logg… Home Assistant 2023.9.0+ Fix from $1,6002023-10-20 MEDIUM 5.3 CVE-2023-41894 Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*… Home Assistant 2023.9.0+ Fix from $1,6002023-10-20 CRITICAL 9.6 CVE-2023-41895 Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in… Home Assistant 2023.9.0+ Fix from $2,3002023-10-19 CRITICAL 9.6 CVE-2023-41897 Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header,… Home Assistant 2023.9.0+ Fix from $2,3002023-10-19 CRITICAL 9.0 CVE-2023-41896 Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`,… Home Assistant 8.2.0 / 2023.8.0+ Fix from $2,3002023-10-19 HIGH 8.8 CVE-2023-44385 The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious l… Home Assistant Companion 2023.7+ Fix from $1,9502023-10-19 HIGH 7.8 CVE-2023-41898 Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL … Home Assistant Companion 2023.9.2+ Fix from $1,9502023-10-19 HIGH 7.2 CVE-2023-41899 Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forger… Home Assistant 2023.9.0+ Fix from $1,9502023-10-19 CRITICAL 10.0 CVE-2023-27482EPSS 72% homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API … Home Assistant 2023.3.0 / 2023.03.1+ Fix from $2,3002023-03-08 HIGH 7.5 CVE-2020-36517 An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about … Home Assistant Patch available Fix from $1,9502022-03-10 MEDIUM 5.3 CVE-2021-3152 Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOT… Home Assistant 2021.1.3+ Fix from $1,6002021-01-26 HIGH 7.5 CVE-2018-21019 Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log… Home Assistant 0.67.0+ Fix from $1,9502019-09-23 MEDIUM 6.1 CVE-2017-16782 In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS. Home Assistant after 0.56.2 Fix from $1,6002017-11-10