VYPR

Core

by Jpettitt

Source repositories

CVEs (22)

  • CVE-2026-64823MedJul 21, 2026
    risk 0.00cvss 4.7epss 0.00

    Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html…

  • CVE-2026-55844HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.00

    Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find…

Page 2 of 2