VulnSea

esphome has 6 CVEs on record between 2024 and 2026. 1 was published in the last 90 days. The median CVSS is 8.1 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: esphome (5), device-builder (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
Last 90 days
1 prev 0

Weakness classes

Products

  • esphome 5
  • device-builder 1
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

esphome vulnerabilities

CVEs affecting esphome, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-59178Critical· 9.8
1w ago

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and…

Midnightesphome · device-builderEPSS 0.42%via NVD
CVE-2026-23833Medium
8mo ago

ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

Sunlitesphome · esphomeEPSS 0.30%via OSV
CVE-2025-57808High· 8.1PoC
1y ago

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

Midnightesphome · esphomeEPSS 1.6%via OSV
CVE-2024-29019High· 8.1
2y ago

ESPHome vulnerable to Authentication bypass via Cross site request forgery

ESPHome vulnerable to Authentication bypass via Cross site request forgery

Twilightesphome · esphomeEPSS 0.27%via OSV
CVE-2024-27287Medium· 6.5
2y ago

esphome vulnerable to stored Cross-site Scripting in edit configuration file API

esphome vulnerable to stored Cross-site Scripting in edit configuration file API

Sunlitesphome · esphomeEPSS 0.68%via OSV
CVE-2024-27081High· 7.2
2y ago

ESPHome vulnerable to remote code execution via arbitrary file write

ESPHome vulnerable to remote code execution via arbitrary file write

Twilightesphome · esphomeEPSS 1.5%via OSV
esphome vulnerabilities (CVEs) · VulnSea