Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-44515 Source A vulnerability in the Nextcloud News RSS reader app allows authenticated users to make the server send HTTP requests to internal network services, enabling scanning of those services. |
Nextcloud | Self-hosted apps | Low | 05.06.2026 |
| CVE-2026-35624 Source A security flaw in Nextcloud Talk allows attackers to bypass access controls and gain unauthorized entry to protected chat rooms by creating rooms with similar names. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-33580 Source A security flaw in OpenClaw allows attackers to guess weak passwords for Nextcloud Talk webhooks through unlimited repeated login attempts, enabling them to create fake webhook events. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-28449 Source A vulnerability in OpenClaw allows attackers to replay previously used Nextcloud Talk webhook requests, leading to duplicate message processing and potential integrity or availability issues. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-28474 Source A security vulnerability in the Nextcloud Talk plugin allows attackers to bypass access controls by changing their display name to match an authorized user, gaining unauthorized access to protected conversations. |
Nextcloud | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2019-25368 Source A security vulnerability in OPNsense 19.1 allows attackers to inject malicious scripts through multiple parameters in the backup diagnostic function and execute them in the browsers of logged-in administrators. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2021-41104 Source A security flaw in ESPHome allows attackers to perform firmware updates through the web interface without entering the configured username and password. Affected versions up to 2021.9.1 with enabled web server and HTTP authentication are vulnerable. |
ESPHome | Self-hosted apps | High | 05.06.2026 |
| CVE-2024-27287 Source ESPHome Dashboard contains a Cross-Site Scripting vulnerability where authenticated users can inject malicious JavaScript code into configuration files to steal session cookies and perform unauthorized actions. |
ESPHome | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2024-29019 Source ESPHome Dashboard component is vulnerable to Cross-Site Request Forgery attacks, allowing attackers to create, edit, or delete configuration files on behalf of logged-in users through malicious web pages. |
ESPHome | Self-hosted apps | High | 05.06.2026 |
| CVE-2024-27081 Source A security vulnerability in ESPHome allows authenticated attackers to read and write arbitrary files in the configuration directory, which can lead to execution of malicious code. |
ESPHome | Self-hosted apps | High | 05.06.2026 |
| CVE-2025-57808 Source ESPHome software on ESP-IDF platform has a web server authentication flaw that allows attackers to access protected functions without valid credentials, including over-the-air updates. |
ESPHome | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-23833 Source A programming flaw in ESPHome allows attackers to crash smart home devices when API encryption is not enabled. |
ESPHome | Self-hosted apps | Low | 05.06.2026 |
| CVE-2024-35184 Source A vulnerability in Paperless-ngx allows attackers to access documents through the API even when remote user API access is explicitly disabled, potentially exposing sensitive document contents. |
Paperless-ngx | Self-hosted apps | Low | 05.06.2026 |
| GHSA-g6fw-vp8x-gr4j Source In Paperless-ngx, logged-in users can access files they don't have permission for through a bulk download feature, leading to unauthorized file access. |
Paperless-ngx | Self-hosted apps | Medium | 05.06.2026 |
| GHSA-6p53-hqqw-8j62 Source Paperless-ngx contains two vulnerabilities that allow authenticated users to inject malicious scripts: through storage path settings or by uploading a manipulated SVG logo file. These scripts can then execute in other users' browsers. |
Paperless-ngx | Self-hosted apps | Medium | 05.06.2026 |
| GHSA-6653-vcx4-69mc Source A security vulnerability in Paperless-ngx's webhook functionality allows attackers to bypass internal network access restrictions using DNS rebinding attacks, potentially enabling access to internal systems despite security controls. |
Paperless-ngx | Self-hosted apps | Low | 05.06.2026 |
| GHSA-24x5-wp64-9fcc Source A vulnerability in Paperless-ngx allows authenticated users to create malicious regular expressions in tags or correspondents that cause extreme CPU usage during document processing, leading to complete service failure. |
Paperless-ngx | Self-hosted apps | Low | 05.06.2026 |
| GHSA-7cq3-mhxq-w946 Source A vulnerability in Paperless-ngx allows attackers to store malicious code in metadata like tags or document types that then executes when other users view the affected interface. |
Paperless-ngx | Self-hosted apps | Low | 05.06.2026 |
| GHSA-28cf-xvcf-hw6m Source A security flaw in Paperless-ngx allows authenticated users to write files to arbitrary locations on the filesystem, including system directories, due to insufficient path validation in the Storage Path feature. |
Paperless-ngx | Self-hosted apps | Medium | 05.06.2026 |
| GHSA-jqwv-hx7q-fxh3 Source A vulnerability in Paperless-ngx allows authenticated users without proper permissions to upload and process documents, even when they should only have read-only access. |
Paperless-ngx | Self-hosted apps | Low | 05.06.2026 |
| GHSA-w47q-3m69-84v8 Source In Paperless-ngx, users with document editing permissions can change the document's owner even though they shouldn't have this privilege. |
Paperless-ngx | Self-hosted apps | Medium | 05.06.2026 |
| GHSA-x395-6h48-wr8v Source A security vulnerability in Paperless-ngx allows any authenticated user to read contents of other users' documents and extract user information, despite lacking proper permissions. |
Paperless-ngx | Self-hosted apps | Medium | 05.06.2026 |
| GHSA-7qqc-wrcw-2fj9 Source A vulnerability in Paperless-ngx allows users to access other users' email passwords by exploiting the email account test function with foreign account IDs without proper permission checks. |
Paperless-ngx | Self-hosted apps | Medium | 05.06.2026 |
| GHSA-386h-chg4-cfw9 Source A vulnerability in Paperless-ngx allows authenticated users to create public links for any documents, even those they lack permission to view, potentially exposing confidential content without authorization. |
Paperless-ngx | Self-hosted apps | Medium | 05.06.2026 |
| GHSA-59xh-5vwx-4c4q Source A vulnerability in Paperless-ngx allows authenticated users with user-adding permissions to create superuser accounts through a type coercion flaw, enabling them to escalate their privileges beyond intended access levels. |
Paperless-ngx | Self-hosted apps | High | 05.06.2026 |
| GHSA-96jx-fj7m-qh6x Source A vulnerability in Paperless-ngx allows authenticated users to view other users' email account metadata and email rules through the global search function, even when they shouldn't have permission to access this information. |
Paperless-ngx | Self-hosted apps | Medium | 05.06.2026 |
| GHSA-8c6x-pfjq-9gr7 Source A vulnerability in Paperless-ngx allows users with delete permissions to remove administrator accounts even though they are not administrators themselves, due to faulty permission checking when deleting user accounts. |
Paperless-ngx | Self-hosted apps | Low | 05.06.2026 |
| CVE-2025-43856 Source Immich photo management software fails to validate the OAuth2 state parameter, allowing attackers to hijack user accounts by tricking victims into opening malicious login links that link accounts together. |
Immich | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-25118 Source The photo management software Immich transmits shared album passwords as visible URL parameters, causing them to be stored in browser history, server logs and other systems where they can be accessed by unauthorized parties. |
Immich | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-23896 Source A security vulnerability in Immich software allows API keys to escalate their own permissions and grant themselves administrator access without proper authorization checks. |
Immich | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-35455 Source A vulnerability in the Immich photo management software allows authenticated users to embed malicious JavaScript code in 360° panorama images that executes in other users' browsers when they enable the OCR text recognition feature. |
Immich | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-40096 Source A vulnerability in Immich photo management software allows registered users to redirect victims to arbitrary websites through manipulated album names, facilitating phishing attacks to steal login credentials. |
Immich | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-53662 Source A vulnerability in Immich allows attackers to gain complete control over user accounts through a malicious link that executes harmful JavaScript code and creates a persistent API key with full permissions. |
Immich | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2023-27482 Source A critical security vulnerability in Home Assistant allowed attackers to bypass authentication and access the Supervisor API. This affected Home Assistant OS and Supervised installations using Supervisor version 2023.03.2 or older. |
Home Assistant Core | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2023-44385 Source A vulnerability in the Home Assistant iOS/macOS app up to version 2023.4 allows attackers to execute arbitrary services on victims' Home Assistant systems through malicious links or QR codes, potentially leading to system compromise. |
Home Assistant Core | Self-hosted apps | High | 05.06.2026 |
| CVE-2023-41899 Source A vulnerability in Home Assistant Core allows attackers to send unauthorized requests to internal Supervisor APIs through the hassio.addon_stdin service, potentially leading to remote code execution. |
Home Assistant Core | Self-hosted apps | Low | 05.06.2026 |
| CVE-2023-41898 Source The Home Assistant Android app up to version 2023.8.2 can load arbitrary URLs in a WebView, allowing attackers to execute malicious JavaScript code and steal user credentials. |
Home Assistant Core | Self-hosted apps | High | 05.06.2026 |
| GHSA-jff5-5j3g-vhqc Source A vulnerability in Home Assistant's GitHub Actions allows attackers to inject commands, potentially stealing secrets and manipulating the repository through the workflow system. |
Home Assistant Core | Self-hosted apps | Low | 05.06.2026 |
| CVE-2023-41897 Source Home Assistant Core doesn't set HTTP security headers like X-Frame-Options, allowing attackers to use clickjacking attacks to trick users into installing malicious add-ons and gain remote code execution on the system. |
Home Assistant Core | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2023-41896 Source A vulnerability in Home Assistant Core allows attackers to create malicious links that force the frontend to connect to a fake WebSocket server, leading to cross-site scripting attacks and complete system takeover. |
Home Assistant Core | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2023-41894 Source Home Assistant Core has a vulnerability where webhooks can be triggered via public URLs without authentication, even when configured as locally accessible only. |
Home Assistant Core | Self-hosted apps | Low | 05.06.2026 |
| CVE-2023-41895 Source A vulnerability in Home Assistant Core allows attackers to execute malicious JavaScript code through manipulated login redirects, potentially leading to complete takeover of the Home Assistant account and installation. |
Home Assistant Core | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2023-41893 Source Home Assistant Core has a vulnerability in its login system where attackers can manipulate redirects to steal access credentials if users click on crafted links and their installation is publicly accessible. |
Home Assistant Core | Self-hosted apps | Low | 05.06.2026 |
| CVE-2023-50715 Source Home Assistant Core displays all active user accounts on the login page without requiring authentication when the request originates from the local network. |
Home Assistant Core | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2025-25305 Source Home Assistant Core has a vulnerability in SSL certificate verification that enables man-in-the-middle attacks. Incorrect use of the ssl parameter in HTTP requests unintentionally disables certificate verification, allowing attackers to intercept encrypted connections. |
Home Assistant Core | Self-hosted apps | High | 05.06.2026 |
| CVE-2025-62172 Source Home Assistant Core is vulnerable to Cross-Site Scripting attacks when malicious HTML content is inserted into entity names, which then gets executed in the Energy dashboard view when users hover over data points. |
Home Assistant Core | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-33044 Source A vulnerability in Home Assistant Core allows authenticated users to inject malicious code into device names, which then executes as a Cross-Site Scripting attack against other users when they hover over data points in map dashboards. |
Home Assistant Core | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-33045 Source A vulnerability in Home Assistant Core allows cross-site scripting attacks through malicious sensor names in history graphs, enabling attackers to execute JavaScript code in other users' sessions and potentially take over accounts. |
Home Assistant Core | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-34205 Source Home Assistant apps using host network mode incorrectly expose internal Docker interfaces to the local network, allowing attackers to access critical functions like shell access without authentication. |
Home Assistant Core | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2026-44698 Source A security vulnerability in Home Assistant Companion apps for Android and iOS allows malicious websites in embedded frames to steal access tokens from logged-in users, granting full access to their smart home systems. |
Home Assistant Core | Self-hosted apps | High | 05.06.2026 |