home-assistant
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 10, 2017 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
Home Assistant has stored XSS in history-graphs
Home Assistant has stored XSS in Map-card through malicious device name
User accounts disclosed to unauthenticated actors on the LAN
Account takeover via auth_callback login in Home Assistant Core
Local-only webhooks externally accessible via SniTun in Home Assistant Core
Cross-site Scripting via auth_callback login in Home Assistant Core
Fake websocket server installation permits full takeover in Home Assistant Core
Monitor home-assistant in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.