Записи ui
120 опубликованных записей вендора ui.
Профиль для исследователя
- Попали в KEV
- 4 · 3,3 %
- С эксплойтом
- 5 · 4,2 %
- Pre-auth RCE
- 16
- С записью об исправлении
- 36,7 %
- Медиана: публикация → KEV
- 33 дн.
Повторяющиеся классы
- CWE-284 Improper Access Control15
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-20 Improper Input Validation6
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')6
- CWE-400 Uncontrolled Resource Consumption5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
120 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
84Срочно | CVE-2026-34910Готовый эксплойт | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute aui · unifi os server · CWE-20 | Критическая10,0 | KEV | 45,8 % | 21 мая 2026 г. |
81Срочно | CVE-2010-5330Готовый эксплойт | On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is notui · airos · CWE-77 | Критическая9,8 | KEV | 39,4 % | 11 июн. 2019 г. |
75На этой неделе | CVE-2026-34908Готовый эксплойт | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthui · unifi os server · CWE-284 | Критическая10,0 | KEV | 15,2 % | 21 мая 2026 г. |
71На этой неделе | CVE-2026-34909Готовый эксплойт | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the uui · unifi os server · CWE-22 | Критическая10,0 | KEV | 1,8 % | 21 мая 2026 г. |
61На этой неделе | CVE-2015-9266Готовый эксплойт | Ubiquiti airOS HTTP(S) unauthenticated arbitrary file uploadui · airmax ac firmware · CWE-22 | Критическая9,8 | — | 74,0 % | 5 сент. 2018 г. |
52В плане | CVE-2025-52665Proof of concept | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, tui · unifi access · CWE-306 | Критическая10,0 | — | 41,0 % | 30 окт. 2025 г. |
41В плане | CVE-2026-50746Proof of concept | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to exui · unifi connect application · CWE-284 | Критическая10,0 | — | 1,7 % | 2 июл. 2026 г. |
40В плане | CVE-2020-8171Эксплойта нет | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax Aiui · airos · CWE-77 | Критическая9,8 | — | 3,9 % | 26 мая 2020 г. |
40В плане | CVE-2020-8234Эксплойта нет | A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be gui · edgemax firmware · CWE-613 | Критическая9,8 | — | 3,4 % | 21 авг. 2020 г. |
40В плане | CVE-2023-1458Эксплойта нет | A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical.ui · edgerouter x firmware · CWE-77 | Критическая9,8 | — | 3,3 % | 25 мар. 2023 г. |
40В плане | CVE-2023-1456Эксплойта нет | A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.ui · edgerouter x firmware · CWE-77 | Критическая9,8 | — | 1,8 % | 25 мар. 2023 г. |
40В плане | CVE-2023-1457Эксплойта нет | A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.ui · edgerouter x firmware · CWE-77 | Критическая9,8 | — | 1,8 % | 25 мар. 2023 г. |
40В плане | CVE-2022-22570Эксплойта нет | A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malui · ua lite firmware · CWE-120 | Критическая10,0 | — | 1,1 % | 1 апр. 2022 г. |
39Наблюдать | CVE-2026-50748Эксплойта нет | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Acceui · unifi access · CWE-20 | Критическая9,9 | — | 1,6 % | 2 июл. 2026 г. |
39Наблюдать | CVE-2023-38034Эксплойта нет | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, couldui · unifi uap firmware · CWE-77 | Критическая9,8 | — | 1,4 % | 10 авг. 2023 г. |
39Наблюдать | CVE-2021-44530Эксплойта нет | An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a ui · unifi network controller · CWE-20 | Критическая9,8 | — | 1,1 % | 14 янв. 2022 г. |
39Наблюдать | CVE-2023-35085Proof of concept | An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default ui · unifi uap firmware · CWE-190 | Критическая9,8 | — | 1,0 % | 10 авг. 2023 г. |
39Наблюдать | CVE-2023-24104Эксплойта нет | Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.ui · unifi dream machine pro firmware | Критическая9,8 | — | 0,8 % | 23 февр. 2023 г. |
39Наблюдать | CVE-2026-54408Эксплойта нет | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to byui · unifi protect · CWE-284 | Критическая9,8 | — | 0,6 % | 2 июл. 2026 г. |
39Наблюдать | CVE-2026-50747Эксплойта нет | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found ui · unifi talk application · CWE-89 | Критическая9,9 | — | 0,5 % | 2 июл. 2026 г. |
39Наблюдать | CVE-2026-55115Эксплойта нет | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Applicatui · unifi protect · CWE-918 | Критическая9,9 | — | 0,5 % | 2 июл. 2026 г. |
39Наблюдать | CVE-2024-54750Эксплойта нет | Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.CWE-798 | Критическая9,8 | — | 0,4 % | 6 дек. 2024 г. |
39Наблюдать | CVE-2026-55116Эксплойта нет | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerabilityui · unifi connect · CWE-284 | Критическая9,8 | — | 0,4 % | 2 июл. 2026 г. |
38Наблюдать | CVE-2021-22943Эксплойта нет | A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network ui · unifi protect · CWE-287 | Критическая9,6 | — | 0,4 % | 31 авг. 2021 г. |
38Наблюдать | CVE-2025-59467Эксплойта нет | A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation ui · argentina afip invoices · CWE-79 | Критическая9,6 | — | 0,3 % | 5 янв. 2026 г. |
- CVE-2026-3491084Срочно
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 46 %ui · unifi os server21 мая 2026 г.
- CVE-2010-533081Срочно
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 39 %ui · airos11 июн. 2019 г.
- CVE-2026-3490875На этой неделе
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 15 %ui · unifi os server21 мая 2026 г.
- CVE-2026-3490971На этой неделе
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the u
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 2 %ui · unifi os server21 мая 2026 г.
- CVE-2015-926661На этой неделе
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
КритическаяCVSS 9,8Готовый эксплойтEPSS 74 %ui · airmax ac firmware5 сент. 2018 г.
- CVE-2025-5266552В плане
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, t
КритическаяCVSS 10,0Proof of conceptEPSS 41 %ui · unifi access30 окт. 2025 г.
- CVE-2026-5074641В плане
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to ex
КритическаяCVSS 10,0Proof of conceptEPSS 2 %ui · unifi connect application2 июл. 2026 г.
- CVE-2020-817140В плане
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax Ai
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %ui · airos26 мая 2020 г.
- CVE-2020-823440В плане
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ui · edgemax firmware21 авг. 2020 г.
- CVE-2023-145840В плане
A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ui · edgerouter x firmware25 мар. 2023 г.
- CVE-2023-145640В плане
A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ui · edgerouter x firmware25 мар. 2023 г.
- CVE-2023-145740В плане
A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ui · edgerouter x firmware25 мар. 2023 г.
- CVE-2022-2257040В плане
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a mal
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %ui · ua lite firmware1 апр. 2022 г.
- CVE-2026-5074839Наблюдать
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Acce
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %ui · unifi access2 июл. 2026 г.
- CVE-2023-3803439Наблюдать
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ui · unifi uap firmware10 авг. 2023 г.
- CVE-2021-4453039Наблюдать
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ui · unifi network controller14 янв. 2022 г.
- CVE-2023-3508539Наблюдать
An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default
КритическаяCVSS 9,8Proof of conceptEPSS 1 %ui · unifi uap firmware10 авг. 2023 г.
- CVE-2023-2410439Наблюдать
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ui · unifi dream machine pro firmware23 февр. 2023 г.
- CVE-2026-5440839Наблюдать
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to by
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ui · unifi protect2 июл. 2026 г.
- CVE-2026-5074739Наблюдать
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %ui · unifi talk application2 июл. 2026 г.
- CVE-2026-5511539Наблюдать
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Applicat
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %ui · unifi protect2 июл. 2026 г.
- CVE-2024-5475039Наблюдать
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %6 дек. 2024 г.
- CVE-2026-5511639Наблюдать
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %ui · unifi connect2 июл. 2026 г.
- CVE-2021-2294338Наблюдать
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %ui · unifi protect31 авг. 2021 г.
- CVE-2025-5946738Наблюдать
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %ui · argentina afip invoices5 янв. 2026 г.