Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Home Assistant

First CVE: Nov 10, 2017Active for: 9 yearsTotal CVEs: 34

Home Assistant is an open-source home-automation platform with a modestly represented vulnerability footprint across its core application, companion applications, and middleware components. The vendor's disclosures span a narrow but strategically important product set deployed in networked smart-home environments, and vulnerabilities merit attention primarily for their role in controlling connected devices and access to automation logic rather than for structural weakness patterns that recur across releases. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Home Assistant over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2017
8 years ago
Most Recent CVE
Jun 23, 2026
31 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-27482CRITICAL
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been
Mar 8, 202310.079NOYES
CVE-2026-54317HIGH
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, Konnected
Jun 23, 20267.634NONO
CVE-2026-54318HIGH
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no
Jun 23, 20267.131NONO
CVE-2021-3152MEDIUM
Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is
Jan 26, 20215.329NOYES
CVE-2023-41897CRITICAL
Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the we
Oct 19, 20239.626NONO
CVE-2023-41895CRITICAL
Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specif
Oct 19, 20239.626NONO
CVE-2020-36517HIGH
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via
Mar 10, 20227.526NONO
CVE-2023-41896CRITICAL
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebS
Oct 19, 20239.025NONO
CVE-2023-44385HIGH
The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when
Oct 19, 20238.824NONO
CVE-2018-21019HIGH
Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py.
Sep 23, 20197.524NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
42%
37%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (15.8%)
Network14 (73.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (10.5%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (52.6%)
Unknown0 (0.0%)
Required9 (47.4%)
Privileges Required
Low3 (15.8%)
High1 (5.3%)
None15 (78.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Home Assistant.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Home Assistant — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Home Assistant's Products

View all 2 CNAs →

Top CWEs