📦 Home Assistant

by Home Assistant

🔍 What is Home Assistant?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-27482

CRITICAL CVSS 10.0 Mar 8, 2023

This vulnerability allows unauthenticated remote attackers to bypass authentication and access the Supervisor API in Home Assistant, potentially gaining full control over the home automation system. I...

CVE-2023-41895

HIGH CVSS 8.8 Oct 19, 2023

This Cross-site Scripting (XSS) vulnerability in Home Assistant allows attackers to execute arbitrary JavaScript on the administration page by exploiting improper validation of redirect URIs. Attacker...

CVE-2023-41897

HIGH CVSS 8.8 Oct 19, 2023

This vulnerability in Home Assistant allows attackers to perform clickjacking attacks by tricking users into clicking malicious elements on a page. This could lead to remote code execution by installi...

CVE-2020-36517

HIGH CVSS 7.5 Mar 10, 2022

This vulnerability allows DNS operators to discover internal network resources through hardcoded DNS resolver configurations in Home Assistant systems. It affects Nabu Casa Home Assistant Operating Sy...