« Volver al listado

Sysadminsmedia

Sysadminsmedia Homebox: vulnerabilidades y CVE

Sysadminsmedia Homebox tiene 10 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses9
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-55473Media (6)0.41%—21 sept 2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4…
CVE-2026-48976Alta (8.1)0.45%—21 sept 2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's…
CVE-2026-48975Alta (8.1)0.49%—21 sept 2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id)…
CVE-2026-48974Media (5.4)0.29%—21 sept 2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an…
CVE-2026-48826Alta (8.1)0.49%—21 sept 2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner…
CVE-2026-40196Alta (8.1)0.40%—17 abr 2026
HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their…
CVE-2026-27981Alta (7.4)0.40%—3 mar 2026
HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header,…
CVE-2026-27600Media (4.3)0.28%—3 mar 2026
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation…
CVE-2026-26272Media (5.4)0.25%—3 mar 2026
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate…
CVE-2025-53108Media (5.3)0.30%—2 jul 2025
HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible for updating and deleting inventory item attachments. This flaw…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services6
  2. T1565.001 Stored Data Manipulation2
  3. T1078.001 Default Accounts1
  4. T1078.002 Domain Accounts1
  5. T1090 Proxy1
  6. T1110.004 Credential Stuffing1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.