Skip to content
Noroxi

ui records

120 published records for vendor ui.

All records

120 records
  • A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a

    CriticalCVSS 10.0KEVWeaponizedEPSS 46%

    ui · unifi os serverMay 21, 2026

  • On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not

    CriticalCVSS 9.8KEVWeaponizedEPSS 39%

    ui · airosJun 11, 2019

  • CVE-2026-34908
    75This week

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth

    CriticalCVSS 10.0KEVWeaponizedEPSS 15%

    ui · unifi os serverMay 21, 2026

  • CVE-2026-34909
    71This week

    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the u

    CriticalCVSS 10.0KEVWeaponizedEPSS 2%

    ui · unifi os serverMay 21, 2026

  • CVE-2015-9266
    61This week

    Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload

    CriticalCVSS 9.8WeaponizedEPSS 74%

    ui · airmax ac firmwareSep 5, 2018

  • A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, t

    CriticalCVSS 10.0Proof of conceptEPSS 41%

    ui · unifi accessOct 30, 2025

  • A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to ex

    CriticalCVSS 10.0Proof of conceptEPSS 2%

    ui · unifi connect applicationJul 2, 2026

  • We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax Ai

    CriticalCVSS 9.8No exploitEPSS 4%

    ui · airosMay 26, 2020

  • A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g

    CriticalCVSS 9.8No exploitEPSS 3%

    ui · edgemax firmwareAug 21, 2020

  • A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical.

    CriticalCVSS 9.8No exploitEPSS 3%

    ui · edgerouter x firmwareMar 25, 2023

  • A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.

    CriticalCVSS 9.8No exploitEPSS 2%

    ui · edgerouter x firmwareMar 25, 2023

  • A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.

    CriticalCVSS 9.8No exploitEPSS 2%

    ui · edgerouter x firmwareMar 25, 2023

  • A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a mal

    CriticalCVSS 10.0No exploitEPSS 1%

    ui · ua lite firmwareApr 1, 2022

  • A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Acce

    CriticalCVSS 9.9No exploitEPSS 2%

    ui · unifi accessJul 2, 2026

  • A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could

    CriticalCVSS 9.8No exploitEPSS 1%

    ui · unifi uap firmwareAug 10, 2023

  • An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a

    CriticalCVSS 9.8No exploitEPSS 1%

    ui · unifi network controllerJan 14, 2022

  • An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    ui · unifi uap firmwareAug 10, 2023

  • Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.

    CriticalCVSS 9.8No exploitEPSS 1%

    ui · unifi dream machine pro firmwareFeb 23, 2023

  • A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to by

    CriticalCVSS 9.8No exploitEPSS 1%

    ui · unifi protectJul 2, 2026

  • A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found

    CriticalCVSS 9.9No exploitEPSS 0%

    ui · unifi talk applicationJul 2, 2026

  • A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Applicat

    CriticalCVSS 9.9No exploitEPSS 0%

    ui · unifi protectJul 2, 2026

  • Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

    CriticalCVSS 9.8No exploitEPSS 0%

    Dec 6, 2024

  • A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    ui · unifi connectJul 2, 2026

  • A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network

    CriticalCVSS 9.6No exploitEPSS 0%

    ui · unifi protectAug 31, 2021

  • A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation

    CriticalCVSS 9.6No exploitEPSS 0%

    ui · argentina afip invoicesJan 5, 2026