HIGH7.6CVE-2026-54317Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN from 0, < 2026.6.0
HIGH7.5CVE-2018-21019Home Assistant information disclosure vulnerability from 0, < 0.67.0
HIGH7.5CVE-2018-21019Home Assistant information disclosure vulnerability from 0, < 0.67.0
HIGH7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
from 0, < 2024.1.6
HIGH7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
from 0, < 2024.1.6
MEDIUM4.3User accounts disclosed to unauthenticated actors on the LAN
from 0, < 2023.12.3
MEDIUM4.3User accounts disclosed to unauthenticated actors on the LAN
from 0, < 2023.12.3
MEDIUM4.3Home Assistant vulnerable to account takeover via auth_callback login
from 0, < 2023.9.0
MEDIUM4.3Home Assistant vulnerable to account takeover via auth_callback login
from 0, < 2023.9.0
—Home Assistant has stored XSS in history-graphs
>= 2025.02, < 2026.01
—Home Assistant has stored XSS in history-graphs
>= 2025.02, < 2026.01
—Home Assistant has stored XSS in Map-card through malicious device name
>= 2020.02, < 2026.01
—Home Assistant has stored XSS in Map-card through malicious device name
>= 2020.02, < 2026.01
—Home Assistant Core before is vulnerable to Directory Traversal
from 0, < 2025.8.0
—Home Assistant Core before is vulnerable to Directory Traversal
from 0, < 2025.8.0
—Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
>= 2025.1.0, < 2025.10.2