CVE-2026-33045
- EPSS 0.03%
- Veröffentlicht 27.03.2026 19:39:03
- Zuletzt bearbeitet 31.03.2026 20:16:27
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it ap...
CVE-2026-33044
- EPSS 0.03%
- Veröffentlicht 27.03.2026 19:35:45
- Zuletzt bearbeitet 31.03.2026 15:42:30
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Sit...
- EPSS 0.01%
- Veröffentlicht 23.12.2025 00:00:00
- Zuletzt bearbeitet 06.01.2026 17:27:46
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.
CVE-2023-50715
- EPSS 0.16%
- Veröffentlicht 15.12.2023 03:15:45
- Zuletzt bearbeitet 21.11.2024 08:37:11
Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch fo...
CVE-2023-41893
- EPSS 0.26%
- Veröffentlicht 20.10.2023 00:15:16
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication wil...
CVE-2023-41894
- EPSS 0.19%
- Veröffentlicht 20.10.2023 00:15:16
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessible from th...
CVE-2023-41895
- EPSS 0.51%
- Veröffentlicht 19.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redir...
- EPSS 0.2%
- Veröffentlicht 19.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The s...
CVE-2023-41897
- EPSS 1.88%
- Veröffentlicht 19.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating h...
CVE-2023-41899
- EPSS 0.17%
- Veröffentlicht 19.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:53
Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able t...