Vulnerabilities

Summary — last 7 days

New vulnerabilities2,739▲ 36 vs. last week
Critical / high1,474▲ 366 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)62▼ 464 vs. last week
–

1,043 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.5)2.4%—Ziroom ZhomeAI9/29/20269/30/2026
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The…
DeferredHigh (8.5)2.5%—Ziroom Zhome A0101AI9/29/202610/1/2026
A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be…
DeferredHigh (8.5)3.0%—Ziroom Zhome A0101AI9/29/202610/2/2026
A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was…
DeferredLow (2.1)0.28%—Coolbeans1212 Mateishomepage WebsiteAI9/29/20269/29/2026
A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been…
DeferredHigh (8.5)2.3%—Ziroom Zhome A0101AI9/28/202610/1/2026
A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was…
DeferredHigh (8.5)2.3%—Ziroom ZhomeAI9/28/20269/29/2026
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor…
DeferredHigh (8.5)2.4%—Ziroom ZhomeAI9/28/20269/29/2026
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…
DeferredHigh (8.5)2.4%—Ziroom Zhome A0101AI9/28/202610/1/2026
A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was…
DeferredHigh (8.5)2.3%—Ziroom ZhomeAI9/28/20269/29/2026
A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument firstLogin results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may…
DeferredHigh (8.5)2.3%—Ziroom ZhomeAI9/28/20269/29/2026
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried…
DeferredMedium (5.9)0.17%—Mh-developer Smart Home ModuleAI9/28/20269/28/2026
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing…
DeferredMedium (6.9)0.37%—Mh-developer Smart Home ModuleAI9/28/20269/28/2026
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access…
DeferredMedium (6)0.21%—Mh-developer Smart Home ModuleAI9/28/20269/28/2026
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in…
DeferredMedium (5.3)0.17%—Mh-developer Smart Home ModuleAI9/28/20269/28/2026
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30
DeferredMedium (6.4)0.21%—Mh-developer Smart Home ModuleAI9/28/20269/28/2026
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building…
DeferredMedium (6.3)0.24%—Mh-developer Smart Home ModuleAI9/28/20269/28/2026
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This…
DeferredHigh (7.7)0.18%—Mh-developer Smart Home ModuleAI9/28/20269/28/2026
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full…
Awaiting AnalysisCritical (9.3)0.39%—Home-assistant Home AssistantAI9/22/20269/23/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without…
Awaiting AnalysisMedium (5.4)0.20%—Home-assistant Home AssistantAI9/22/20269/25/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ipp/config_flow.py, where async_step_zeroconf passed attacker-controlled host, port,…
DeferredMedium (6)0.41%—Sysadminsmedia HomeboxAI9/21/20269/29/2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedded in the NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. An authenticated user…
DeferredHigh (8.1)0.45%—Sysadminsmedia HomeboxAI9/21/20269/23/2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier…
DeferredHigh (8.1)0.49%—Sysadminsmedia HomeboxAI9/21/20269/23/2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's…
DeferredMedium (5.4)0.29%—Sysadminsmedia HomeboxAI9/21/20269/29/2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force…
DeferredHigh (8.1)0.49%—Sysadminsmedia HomeboxAI9/21/20269/23/2026
HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through…
AnalyzedHigh (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+3729/17/20269/22/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.