ui records
120 published records for vendor ui.
Researcher profile
- Entered KEV
- 4 · 3.3%
- Weaponized
- 5 · 4.2%
- Pre-auth RCE
- 16
- With a fix record
- 36.7%
- Median publish → KEV
- 33 days
Recurring classes
- CWE-284 Improper Access Control15
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-20 Improper Input Validation6
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')6
- CWE-400 Uncontrolled Resource Consumption5
The weakness classes this vendor ships most often: where to look.
CWEAll records
120 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
84Now | CVE-2026-34910Weaponized | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute aui · unifi os server · CWE-20 | Critical10.0 | KEV | 45.8% | May 21, 2026 |
81Now | CVE-2010-5330Weaponized | On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is notui · airos · CWE-77 | Critical9.8 | KEV | 39.4% | Jun 11, 2019 |
75This week | CVE-2026-34908Weaponized | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthui · unifi os server · CWE-284 | Critical10.0 | KEV | 15.2% | May 21, 2026 |
71This week | CVE-2026-34909Weaponized | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the uui · unifi os server · CWE-22 | Critical10.0 | KEV | 1.8% | May 21, 2026 |
61This week | CVE-2015-9266Weaponized | Ubiquiti airOS HTTP(S) unauthenticated arbitrary file uploadui · airmax ac firmware · CWE-22 | Critical9.8 | — | 74.0% | Sep 5, 2018 |
52Plan | CVE-2025-52665Proof of concept | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, tui · unifi access · CWE-306 | Critical10.0 | — | 41.0% | Oct 30, 2025 |
41Plan | CVE-2026-50746Proof of concept | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to exui · unifi connect application · CWE-284 | Critical10.0 | — | 1.7% | Jul 2, 2026 |
40Plan | CVE-2020-8171No exploit | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax Aiui · airos · CWE-77 | Critical9.8 | — | 3.9% | May 26, 2020 |
40Plan | CVE-2020-8234No exploit | A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be gui · edgemax firmware · CWE-613 | Critical9.8 | — | 3.4% | Aug 21, 2020 |
40Plan | CVE-2023-1458No exploit | A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical.ui · edgerouter x firmware · CWE-77 | Critical9.8 | — | 3.3% | Mar 25, 2023 |
40Plan | CVE-2023-1456No exploit | A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.ui · edgerouter x firmware · CWE-77 | Critical9.8 | — | 1.8% | Mar 25, 2023 |
40Plan | CVE-2023-1457No exploit | A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.ui · edgerouter x firmware · CWE-77 | Critical9.8 | — | 1.8% | Mar 25, 2023 |
40Plan | CVE-2022-22570No exploit | A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malui · ua lite firmware · CWE-120 | Critical10.0 | — | 1.1% | Apr 1, 2022 |
39Monitor | CVE-2026-50748No exploit | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Acceui · unifi access · CWE-20 | Critical9.9 | — | 1.6% | Jul 2, 2026 |
39Monitor | CVE-2023-38034No exploit | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, couldui · unifi uap firmware · CWE-77 | Critical9.8 | — | 1.4% | Aug 10, 2023 |
39Monitor | CVE-2021-44530No exploit | An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a ui · unifi network controller · CWE-20 | Critical9.8 | — | 1.1% | Jan 14, 2022 |
39Monitor | CVE-2023-35085Proof of concept | An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default ui · unifi uap firmware · CWE-190 | Critical9.8 | — | 1.0% | Aug 10, 2023 |
39Monitor | CVE-2023-24104No exploit | Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.ui · unifi dream machine pro firmware | Critical9.8 | — | 0.8% | Feb 23, 2023 |
39Monitor | CVE-2026-54408No exploit | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to byui · unifi protect · CWE-284 | Critical9.8 | — | 0.6% | Jul 2, 2026 |
39Monitor | CVE-2026-50747No exploit | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found ui · unifi talk application · CWE-89 | Critical9.9 | — | 0.5% | Jul 2, 2026 |
39Monitor | CVE-2026-55115No exploit | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Applicatui · unifi protect · CWE-918 | Critical9.9 | — | 0.5% | Jul 2, 2026 |
39Monitor | CVE-2024-54750No exploit | Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.CWE-798 | Critical9.8 | — | 0.4% | Dec 6, 2024 |
39Monitor | CVE-2026-55116No exploit | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerabilityui · unifi connect · CWE-284 | Critical9.8 | — | 0.4% | Jul 2, 2026 |
38Monitor | CVE-2021-22943No exploit | A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network ui · unifi protect · CWE-287 | Critical9.6 | — | 0.4% | Aug 31, 2021 |
38Monitor | CVE-2025-59467No exploit | A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation ui · argentina afip invoices · CWE-79 | Critical9.6 | — | 0.3% | Jan 5, 2026 |
- CVE-2026-3491084Now
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a
CriticalCVSS 10.0KEVWeaponizedEPSS 46%ui · unifi os serverMay 21, 2026
- CVE-2010-533081Now
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not
CriticalCVSS 9.8KEVWeaponizedEPSS 39%ui · airosJun 11, 2019
- CVE-2026-3490875This week
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth
CriticalCVSS 10.0KEVWeaponizedEPSS 15%ui · unifi os serverMay 21, 2026
- CVE-2026-3490971This week
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the u
CriticalCVSS 10.0KEVWeaponizedEPSS 2%ui · unifi os serverMay 21, 2026
- CVE-2015-926661This week
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
CriticalCVSS 9.8WeaponizedEPSS 74%ui · airmax ac firmwareSep 5, 2018
- CVE-2025-5266552Plan
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, t
CriticalCVSS 10.0Proof of conceptEPSS 41%ui · unifi accessOct 30, 2025
- CVE-2026-5074641Plan
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to ex
CriticalCVSS 10.0Proof of conceptEPSS 2%ui · unifi connect applicationJul 2, 2026
- CVE-2020-817140Plan
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax Ai
CriticalCVSS 9.8No exploitEPSS 4%ui · airosMay 26, 2020
- CVE-2020-823440Plan
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g
CriticalCVSS 9.8No exploitEPSS 3%ui · edgemax firmwareAug 21, 2020
- CVE-2023-145840Plan
A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical.
CriticalCVSS 9.8No exploitEPSS 3%ui · edgerouter x firmwareMar 25, 2023
- CVE-2023-145640Plan
A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.
CriticalCVSS 9.8No exploitEPSS 2%ui · edgerouter x firmwareMar 25, 2023
- CVE-2023-145740Plan
A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.
CriticalCVSS 9.8No exploitEPSS 2%ui · edgerouter x firmwareMar 25, 2023
- CVE-2022-2257040Plan
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a mal
CriticalCVSS 10.0No exploitEPSS 1%ui · ua lite firmwareApr 1, 2022
- CVE-2026-5074839Monitor
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Acce
CriticalCVSS 9.9No exploitEPSS 2%ui · unifi accessJul 2, 2026
- CVE-2023-3803439Monitor
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could
CriticalCVSS 9.8No exploitEPSS 1%ui · unifi uap firmwareAug 10, 2023
- CVE-2021-4453039Monitor
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a
CriticalCVSS 9.8No exploitEPSS 1%ui · unifi network controllerJan 14, 2022
- CVE-2023-3508539Monitor
An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default
CriticalCVSS 9.8Proof of conceptEPSS 1%ui · unifi uap firmwareAug 10, 2023
- CVE-2023-2410439Monitor
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
CriticalCVSS 9.8No exploitEPSS 1%ui · unifi dream machine pro firmwareFeb 23, 2023
- CVE-2026-5440839Monitor
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to by
CriticalCVSS 9.8No exploitEPSS 1%ui · unifi protectJul 2, 2026
- CVE-2026-5074739Monitor
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found
CriticalCVSS 9.9No exploitEPSS 0%ui · unifi talk applicationJul 2, 2026
- CVE-2026-5511539Monitor
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Applicat
CriticalCVSS 9.9No exploitEPSS 0%ui · unifi protectJul 2, 2026
- CVE-2024-5475039Monitor
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
CriticalCVSS 9.8No exploitEPSS 0%Dec 6, 2024
- CVE-2026-5511639Monitor
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%ui · unifi connectJul 2, 2026
- CVE-2021-2294338Monitor
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network
CriticalCVSS 9.6No exploitEPSS 0%ui · unifi protectAug 31, 2021
- CVE-2025-5946738Monitor
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation
CriticalCVSS 9.6No exploitEPSS 0%ui · argentina afip invoicesJan 5, 2026