Ui
ui
118 CVEs • 310 products
Products (310)
Click to collapseToggle
Products (310)
Click to collapse
CVEs (118)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ui 32Enterprise Firewall Core Firmware Enterprise Fortress Gateway FirmwareEnterprise Network Video Recorder Core Firmware+29 moreJul 10, 2026 Jul 2, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. |
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. |
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. |
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. |
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. |
1Ui 31Enterprise Fortress Gateway Firmware Enterprise Network Video Recorder Core FirmwareEnterprise Network Video Recorder Firmware+28 moreJul 23, 2026 May 22, 2026 N/A· v4 7.7 HIGH· v3 N/A· v2 A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitiv...Show more |
1Ui 31Enterprise Fortress Gateway Firmware Enterprise Network Video Recorder Core FirmwareEnterprise Network Video Recorder Firmware+28 moreJul 23, 2026 May 22, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. |
1Ui 32Enterprise Fortress Gateway Firmware Enterprise Network Video Recorder Core FirmwareEnterprise Network Video Recorder Firmware+29 moreJul 23, 2026 May 22, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. |
1Ui 31Enterprise Fortress Gateway Firmware Enterprise Network Video Recorder Core FirmwareEnterprise Network Video Recorder Firmware+28 moreJul 23, 2026 May 22, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. |
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. |
1Ui 4Airfiber Af60 Xg Firmware Airfiber Af60 FirmwareAirmax Ac Firmware+1 moreJun 17, 2026 Jan 8, 2026 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products:...Show more |
1Ui 4Ubb Xg Firmware Ubb FirmwareUdb Pro Sector Firmware+1 moreJun 17, 2026 Jan 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products: UBB-X...Show more |
1Ui 1Unifi Connect Ev Station Lite Firmware Jun 17, 2026 Jan 5, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a device that was only adopted via Ethernet. |
A malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery protocol causing it to restart. Affected Products: UniFi Protect Application...Show more |
A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerability in the Unifi Protect Application (Version 6.1.79 and earli...Show more |
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This pl...Show more |
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability w...Show more |
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privile...Show more |
Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to d...Show more |
1Ui 2Unifi Switch Firmware Unifi Uap FirmwareJun 17, 2026 Aug 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Poi...Show more |