home-assistant
ICS / OT / IoToss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting home-assistant.
- CVE-2026-91129Home Assistant: mDNS Server-Side Request Forgery5.4
- CVE-2026-91130Home Assistant: XSS in Statistics Graph Card
- CVE-2026-66061Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution7.1
- CVE-2026-66060Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers7.1
- CVE-2026-59717Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing4.3
- CVE-2026-64825Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload9.3
- CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore8.4
- CVE-2026-64823Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI4.7
- CVE-2026-55844Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data7.5
- CVE-2026-54318Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location7.1
- CVE-2026-54317Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN7.6
- CVE-2026-44698Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection8.3
- CVE-2021-47942Home Assistant Community Store 1.10.0 Path Traversal Account Takeover7.5
- CVE-2026-34205Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode9.6
- CVE-2026-33045Home Assistant has stored XSS in history-graphs5.4