İçeriğe atla
Noroxi

ui kayıtları

ui üreticisine ait 120 yayımlanmış kayıt.

Tüm kayıtlar

120 kayıt
  • A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %46

    ui · unifi os server21 May 2026

  • On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %39

    ui · airos11 Haz 2019

  • CVE-2026-34908
    75Bu hafta

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %15

    ui · unifi os server21 May 2026

  • CVE-2026-34909
    71Bu hafta

    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the u

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %2

    ui · unifi os server21 May 2026

  • CVE-2015-9266
    61Bu hafta

    Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload

    KritikCVSS 9,8SilahlaştırılmışEPSS %74

    ui · airmax ac firmware5 Eyl 2018

  • CVE-2025-52665
    52Planlayın

    A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, t

    KritikCVSS 10,0Kavram kanıtıEPSS %41

    ui · unifi access30 Eki 2025

  • CVE-2026-50746
    41Planlayın

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to ex

    KritikCVSS 10,0Kavram kanıtıEPSS %2

    ui · unifi connect application2 Tem 2026

  • CVE-2020-8171
    40Planlayın

    We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax Ai

    KritikCVSS 9,8İstismar yokEPSS %4

    ui · airos26 May 2020

  • CVE-2020-8234
    40Planlayın

    A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g

    KritikCVSS 9,8İstismar yokEPSS %3

    ui · edgemax firmware21 Ağu 2020

  • CVE-2023-1458
    40Planlayın

    A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical.

    KritikCVSS 9,8İstismar yokEPSS %3

    ui · edgerouter x firmware25 Mar 2023

  • CVE-2023-1456
    40Planlayın

    A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.

    KritikCVSS 9,8İstismar yokEPSS %2

    ui · edgerouter x firmware25 Mar 2023

  • CVE-2023-1457
    40Planlayın

    A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6.

    KritikCVSS 9,8İstismar yokEPSS %2

    ui · edgerouter x firmware25 Mar 2023

  • CVE-2022-22570
    40Planlayın

    A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a mal

    KritikCVSS 10,0İstismar yokEPSS %1

    ui · ua lite firmware1 Nis 2022

  • CVE-2026-50748
    39İzleyin

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Acce

    KritikCVSS 9,9İstismar yokEPSS %2

    ui · unifi access2 Tem 2026

  • CVE-2023-38034
    39İzleyin

    A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could

    KritikCVSS 9,8İstismar yokEPSS %1

    ui · unifi uap firmware10 Ağu 2023

  • CVE-2021-44530
    39İzleyin

    An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a

    KritikCVSS 9,8İstismar yokEPSS %1

    ui · unifi network controller14 Oca 2022

  • CVE-2023-35085
    39İzleyin

    An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    ui · unifi uap firmware10 Ağu 2023

  • CVE-2023-24104
    39İzleyin

    Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.

    KritikCVSS 9,8İstismar yokEPSS %1

    ui · unifi dream machine pro firmware23 Şub 2023

  • CVE-2026-54408
    39İzleyin

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to by

    KritikCVSS 9,8İstismar yokEPSS %1

    ui · unifi protect2 Tem 2026

  • CVE-2026-50747
    39İzleyin

    A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found

    KritikCVSS 9,9İstismar yokEPSS %0

    ui · unifi talk application2 Tem 2026

  • CVE-2026-55115
    39İzleyin

    A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Applicat

    KritikCVSS 9,9İstismar yokEPSS %0

    ui · unifi protect2 Tem 2026

  • CVE-2024-54750
    39İzleyin

    Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

    KritikCVSS 9,8İstismar yokEPSS %0

    6 Ara 2024

  • CVE-2026-55116
    39İzleyin

    A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    ui · unifi connect2 Tem 2026

  • CVE-2021-22943
    38İzleyin

    A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network

    KritikCVSS 9,6İstismar yokEPSS %0

    ui · unifi protect31 Ağu 2021

  • CVE-2025-59467
    38İzleyin

    A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation

    KritikCVSS 9,6İstismar yokEPSS %0

    ui · argentina afip invoices5 Oca 2026