Vulnerabilidades en Home-Assistant
28 resultadosAnálisis Vexday
Home-Assistant apresenta presença mínima na base de vulnerabilidades com apenas 1 CVE registrado, ainda sem sinais de exploração ativa em campo. A vulnerabilidade, publicada nos últimos 90 dias, refere-se a traversal de diretórios (CWE-22), de severidade não-crítica, representando risco moderado que requer atenção imediata apenas se o produto for crítico na sua infraestrutura.
CVE-2025-25305HIGHSSL validation for outgoing requests in Home Assistant Core and used libs not correctEPSS 0.3%CVE-2026-33045HIGHHome Assistant has stored XSS in history-graphsEPSS 0.2%CVE-2026-91129MEDIUMHome Assistant: mDNS Server-Side Request ForgeryEPSS 0.2%CVE-2026-54318HIGHHome Assistant: Exported BroadcastReceiver allows local apps to spoof device locationEPSS 0.2%CVE-2026-66060HIGHHome Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callersEPSS 0.2%CVE-2026-66061HIGHHome Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation executionEPSS 0.2%CVE-2026-44698HIGHHome Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionEPSS 0.2%CVE-2023-41898HIGH Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for AndroidEPSS 0.2%