← Back

Ui

ui

87 CVEs • 246 products

Products (246)

Click to collapse
Toggle
Er X Firmware
er-x_firmware
Unifi Video
unifi_video
Unifi Protect
unifi_protect
Airos
airos
Desktop
desktop
Edgeswitch X
edgeswitch_x
Edgeos
edgeos
Er 4 Firmware
er-4_firmware
Aircam
aircam
Aircam Dome
aircam_dome
Aircam Mini
aircam_mini
Edgeswitch
edgeswitch
Ucrm
ucrm
Af5x Firmware
af5x_firmware
Af5 Firmware
af5_firmware
Unifi Firmware
unifi_firmware
Ep R6 Firmware
ep-r6_firmware
Er 8 Firmware
er-8_firmware
Ep R8 Firmware
ep-r8_firmware
Mfi Controller
mfi_controller
Cloud Key Gen2
cloud_key_gen2
Unifi Talk
unifi_talk
Af 2x Firmware
af-2x_firmware
Usg Firmware
usg_firmware
Unifi Os
unifi_os
Unifi Access
unifi_access
Ubb Firmware
ubb_firmware
Airmax Ac
airmax_ac
Airmax M Xm
airmax_m_xm
Airmax M Xw
airmax_m_xw
Airmax M Ti
airmax_m_ti
Airgateway
airgateway
Airfiber Af24
airfiber_af24
Af5x
af5x
Af5
af5
Airmax M
airmax_m
Edgeswitch Xp
edgeswitch_xp
Edgemax
edgemax
Erlite 3
erlite-3
Unifi 52
unifi_52
Ep S16.
ep-s16.
Es 12f
es-12f
Es 16 150w
es-16-150w
Es 16 Xg
es-16-xg

CVEs (87)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ui
1Edgeswitch Firmware
Nov 21, 2024
Jun 20, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability due to lack of protection on the admin CLI, leading to code execution and privilege escalation greater...Show more
Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability due to lack of protection on the admin CLI, leading to code execution and privilege escalation greater than administrators themselves are allowed. An attacker with access to an admin account could escape the restricted CLI and execute arbitrary code.Show less
1Ui
1Edgeos
Nov 21, 2024
Mar 22, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker w...Show more
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker with access to an operator (read-only) account could escalate privileges to admin (root) access in the system.Show less
1Ui
1Unifi Video
May 13, 2026
Dec 27, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
1Ui
1Unifi Controller
May 6, 2026
Jul 29, 2014
N/A· v4
N/A· v3
2.6 LOW· v2
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
1Ui
1Unifi Video
May 6, 2026
Jul 25, 2014
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attacke...Show more
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.Show less
1Ui
1Unifi Controller
Apr 29, 2026
Dec 31, 2013
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted clien...Show more
Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname.Show less
1Ui
4Aircam
Aircam DomeAircam Mini+1 more
Apr 29, 2026
Jul 18, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allows remote attackers to execute arbitrary code via a long rtsp: URI in a DESCRIBE request.