ui kayıtları
ui üreticisine ait 120 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %3,3
- Silahlaştırılmış
- 5 · %4,2
- Pre-auth RCE
- 16
- Düzeltme kaydı olan
- %36,7
- Yayından KEV’e ortanca
- 33 gün
Tekrar eden sınıflar
- CWE-284 Improper Access Control15
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-20 Improper Input Validation6
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')6
- CWE-400 Uncontrolled Resource Consumption5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
120 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
84Hemen | CVE-2026-34910Silahlaştırılmış | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute aui · unifi os server · CWE-20 | Kritik10,0 | KEV | %45,8 | 21 May 2026 |
81Hemen | CVE-2010-5330Silahlaştırılmış | On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is notui · airos · CWE-77 | Kritik9,8 | KEV | %39,4 | 11 Haz 2019 |
75Bu hafta | CVE-2026-34908Silahlaştırılmış | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthui · unifi os server · CWE-284 | Kritik10,0 | KEV | %15,2 | 21 May 2026 |
71Bu hafta | CVE-2026-34909Silahlaştırılmış | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the uui · unifi os server · CWE-22 | Kritik10,0 | KEV | %1,8 | 21 May 2026 |
61Bu hafta | CVE-2015-9266Silahlaştırılmış | Ubiquiti airOS HTTP(S) unauthenticated arbitrary file uploadui · airmax ac firmware · CWE-22 | Kritik9,8 | — | %74,0 | 5 Eyl 2018 |
52Planlayın | CVE-2025-52665Kavram kanıtı | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, tui · unifi access · CWE-306 | Kritik10,0 | — | %41,0 | 30 Eki 2025 |
41Planlayın | CVE-2026-50746Kavram kanıtı | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to exui · unifi connect application · CWE-284 | Kritik10,0 | — | %1,7 | 2 Tem 2026 |
40Planlayın | CVE-2020-8171İstismar yok | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax Aiui · airos · CWE-77 | Kritik9,8 | — | %3,9 | 26 May 2020 |
40Planlayın | CVE-2020-8234İstismar yok | A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be gui · edgemax firmware · CWE-613 | Kritik9,8 | — | %3,4 | 21 Ağu 2020 |
40Planlayın | CVE-2023-1458İstismar yok | A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical.ui · edgerouter x firmware · CWE-77 | Kritik9,8 | — | %3,3 | 25 Mar 2023 |
40Planlayın | CVE-2023-1456İstismar yok | A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.ui · edgerouter x firmware · CWE-77 | Kritik9,8 | — | %1,8 | 25 Mar 2023 |
40Planlayın | CVE-2023-1457İstismar yok | A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.ui · edgerouter x firmware · CWE-77 | Kritik9,8 | — | %1,8 | 25 Mar 2023 |
40Planlayın | CVE-2022-22570İstismar yok | A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malui · ua lite firmware · CWE-120 | Kritik10,0 | — | %1,1 | 1 Nis 2022 |
39İzleyin | CVE-2026-50748İstismar yok | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Acceui · unifi access · CWE-20 | Kritik9,9 | — | %1,6 | 2 Tem 2026 |
39İzleyin | CVE-2023-38034İstismar yok | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, couldui · unifi uap firmware · CWE-77 | Kritik9,8 | — | %1,4 | 10 Ağu 2023 |
39İzleyin | CVE-2021-44530İstismar yok | An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a ui · unifi network controller · CWE-20 | Kritik9,8 | — | %1,1 | 14 Oca 2022 |
39İzleyin | CVE-2023-35085Kavram kanıtı | An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default ui · unifi uap firmware · CWE-190 | Kritik9,8 | — | %1,0 | 10 Ağu 2023 |
39İzleyin | CVE-2023-24104İstismar yok | Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.ui · unifi dream machine pro firmware | Kritik9,8 | — | %0,8 | 23 Şub 2023 |
39İzleyin | CVE-2026-54408İstismar yok | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to byui · unifi protect · CWE-284 | Kritik9,8 | — | %0,6 | 2 Tem 2026 |
39İzleyin | CVE-2026-50747İstismar yok | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found ui · unifi talk application · CWE-89 | Kritik9,9 | — | %0,5 | 2 Tem 2026 |
39İzleyin | CVE-2026-55115İstismar yok | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Applicatui · unifi protect · CWE-918 | Kritik9,9 | — | %0,5 | 2 Tem 2026 |
39İzleyin | CVE-2024-54750İstismar yok | Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.CWE-798 | Kritik9,8 | — | %0,4 | 6 Ara 2024 |
39İzleyin | CVE-2026-55116İstismar yok | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerabilityui · unifi connect · CWE-284 | Kritik9,8 | — | %0,4 | 2 Tem 2026 |
38İzleyin | CVE-2021-22943İstismar yok | A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network ui · unifi protect · CWE-287 | Kritik9,6 | — | %0,4 | 31 Ağu 2021 |
38İzleyin | CVE-2025-59467İstismar yok | A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation ui · argentina afip invoices · CWE-79 | Kritik9,6 | — | %0,3 | 5 Oca 2026 |
- CVE-2026-3491084Hemen
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %46ui · unifi os server21 May 2026
- CVE-2010-533081Hemen
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %39ui · airos11 Haz 2019
- CVE-2026-3490875Bu hafta
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %15ui · unifi os server21 May 2026
- CVE-2026-3490971Bu hafta
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the u
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %2ui · unifi os server21 May 2026
- CVE-2015-926661Bu hafta
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
KritikCVSS 9,8SilahlaştırılmışEPSS %74ui · airmax ac firmware5 Eyl 2018
- CVE-2025-5266552Planlayın
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, t
KritikCVSS 10,0Kavram kanıtıEPSS %41ui · unifi access30 Eki 2025
- CVE-2026-5074641Planlayın
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to ex
KritikCVSS 10,0Kavram kanıtıEPSS %2ui · unifi connect application2 Tem 2026
- CVE-2020-817140Planlayın
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax Ai
KritikCVSS 9,8İstismar yokEPSS %4ui · airos26 May 2020
- CVE-2020-823440Planlayın
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g
KritikCVSS 9,8İstismar yokEPSS %3ui · edgemax firmware21 Ağu 2020
- CVE-2023-145840Planlayın
A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical.
KritikCVSS 9,8İstismar yokEPSS %3ui · edgerouter x firmware25 Mar 2023
- CVE-2023-145640Planlayın
A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.
KritikCVSS 9,8İstismar yokEPSS %2ui · edgerouter x firmware25 Mar 2023
- CVE-2023-145740Planlayın
A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.
KritikCVSS 9,8İstismar yokEPSS %2ui · edgerouter x firmware25 Mar 2023
- CVE-2022-2257040Planlayın
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a mal
KritikCVSS 10,0İstismar yokEPSS %1ui · ua lite firmware1 Nis 2022
- CVE-2026-5074839İzleyin
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Acce
KritikCVSS 9,9İstismar yokEPSS %2ui · unifi access2 Tem 2026
- CVE-2023-3803439İzleyin
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could
KritikCVSS 9,8İstismar yokEPSS %1ui · unifi uap firmware10 Ağu 2023
- CVE-2021-4453039İzleyin
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a
KritikCVSS 9,8İstismar yokEPSS %1ui · unifi network controller14 Oca 2022
- CVE-2023-3508539İzleyin
An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default
KritikCVSS 9,8Kavram kanıtıEPSS %1ui · unifi uap firmware10 Ağu 2023
- CVE-2023-2410439İzleyin
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
KritikCVSS 9,8İstismar yokEPSS %1ui · unifi dream machine pro firmware23 Şub 2023
- CVE-2026-5440839İzleyin
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to by
KritikCVSS 9,8İstismar yokEPSS %1ui · unifi protect2 Tem 2026
- CVE-2026-5074739İzleyin
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found
KritikCVSS 9,9İstismar yokEPSS %0ui · unifi talk application2 Tem 2026
- CVE-2026-5511539İzleyin
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Applicat
KritikCVSS 9,9İstismar yokEPSS %0ui · unifi protect2 Tem 2026
- CVE-2024-5475039İzleyin
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
KritikCVSS 9,8İstismar yokEPSS %06 Ara 2024
- CVE-2026-5511639İzleyin
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0ui · unifi connect2 Tem 2026
- CVE-2021-2294338İzleyin
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network
KritikCVSS 9,6İstismar yokEPSS %0ui · unifi protect31 Ağu 2021
- CVE-2025-5946738İzleyin
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation
KritikCVSS 9,6İstismar yokEPSS %0ui · argentina afip invoices5 Oca 2026