Vulnerabilidades en Home-Assistant
26 resultadosAnálisis Vexday
Home-Assistant apresenta presença mínima na base de vulnerabilidades com apenas 1 CVE registrado, ainda sem sinais de exploração ativa em campo. A vulnerabilidade, publicada nos últimos 90 dias, refere-se a traversal de diretórios (CWE-22), de severidade não-crítica, representando risco moderado que requer atenção imediata apenas se o produto for crítico na sua infraestrutura.
CVE-2023-27482CRITICALhomeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the SupervEPSS 72.0%CVE-2023-41897HIGHLack of XFO header allows clickjacking in Home Assistant CoreEPSS 0.9%CVE-2023-50715MEDIUMUser accounts disclosed to unauthenticated actors on the LANEPSS 0.9%CVE-2023-41895HIGHCross-site Scripting via auth_callback login in Home Assistant CoreEPSS 0.7%CVE-2026-64824CRITICALHome Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreEPSS 0.6%CVE-2025-62172HIGHHome Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity NameEPSS 0.5%CVE-2021-47942HIGHHome Assistant Community Store 1.10.0 Path Traversal Account TakeoverEPSS 0.5%CVE-2026-64825CRITICALHome Assistant Core < 2026.6.0 Path Traversal File Write via Backup UploadEPSS 0.5%CVE-2023-41899MEDIUMPartial Server-Side Request Forgery in Home Assistant Core EPSS 0.5%CVE-2023-41894MEDIUMLocal-only webhooks externally accessible via SniTun in Home Assistant CoreEPSS 0.4%CVE-2023-41893MEDIUMAccount takeover via auth_callback login in Home Assistant CoreEPSS 0.4%CVE-2026-54317HIGHHome Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANEPSS 0.3%CVE-2023-44385HIGHClient-Side Request Forgery in Home Assistant iOS/macOS native AppsEPSS 0.3%CVE-2023-41896HIGHFake websocket server installation permits full takeover in Home Assistant CoreEPSS 0.3%CVE-2026-34205CRITICALHome Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network ModeEPSS 0.3%CVE-2026-33044HIGHHome Assistant has stored XSS in Map-card through malicious device nameEPSS 0.2%CVE-2025-25305HIGHSSL validation for outgoing requests in Home Assistant Core and used libs not correctEPSS 0.2%CVE-2026-59717MEDIUMHome Assistant Companion: `homeassistant://invite` Deep Link Credential PhishingEPSS 0.2%CVE-2026-33045HIGHHome Assistant has stored XSS in history-graphsEPSS 0.2%CVE-2026-64823LOWHome Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URIEPSS 0.2%