Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · ui

ui

· 13 Critical

Total CVEs

89

Critical

13

Products

249

Search All CVEs →

89

Products (249)

er-x-sfp9 CVEser-x9 CVEser-x-sfp firmware8 CVEser-x firmware8 CVEsunifi video7 CVEsunifi protect7 CVEsunifi controller6 CVEses-48-500w5 CVEses-24-250w5 CVEsairos5 CVEses-16-150w5 CVEses-12f5 CVEses-24-500w5 CVEses-24-lite5 CVEsedgeswitch firmware5 CVEses-8-150w5 CVEses-48-lite5 CVEses-48-750w5 CVEsunifi network application4 CVEsedgemax edgerouter firmware4 CVEsairmax ac4 CVEsunifi dream machine pro4 CVEsdesktop4 CVEsnbm3653 CVEsnbm33 CVEsnbe-m5-193 CVEsnbe-m5-163 CVEsairgrid m3 CVEsairgrid m23 CVEsairgrid m53 CVEsairmax ac firmware3 CVEsunifi switch firmware3 CVEsnbe-m2-133 CVEsnb-5g253 CVEsnb-5g223 CVEsnb-2g183 CVEsm9003 CVEsm53 CVEsm3653 CVEsm33 CVEsm23 CVEsar3 CVEsar-hp3 CVEslocom93 CVEsbm2-ti3 CVEsbm2hp3 CVEsbm5-ti3 CVEsbm5hp3 CVEsag-hp-2g163 CVEslocom53 CVEslocom23 CVEslitestation m53 CVEslbem5-233 CVEsis-m53 CVEsedgemax edgerouter3 CVEsag-hp-2g203 CVEsedgerouter x3 CVEsedgerouter x firmware3 CVEsag-hp-5g273 CVEsedgeswitch x3 CVEsag-hp-5g233 CVEsep-s163 CVEsubb-xg3 CVEsubb3 CVEses-16-xg3 CVEsrm5-ti3 CVEsrm2-ti3 CVEspower ap n3 CVEspicom2hp3 CVEspbm53 CVEspbm3653 CVEspbm103 CVEspbe-m5-6203 CVEspbe-m5-400-iso3 CVEspbe-m5-4003 CVEspbe-m5-300-iso3 CVEspbe-m5-3003 CVEspbe-m2-4003 CVEsnsm53 CVEsnsm3653 CVEsnsm33 CVEsnsm23 CVEsnbm93 CVEsuwb-xg2 CVEsaircam2 CVEsairmax m2 CVEscamera g3 flex2 CVEscamera g3 flex firmware2 CVEscloud key gen22 CVEscloud key gen2 plus2 CVEsedgemax firmware2 CVEsedgeos2 CVEsedgeswitch2 CVEsep-16-xg2 CVEsep-s16.2 CVEser-122 CVEser-12 firmware2 CVEser-42 CVEser-4 firmware2 CVEser-6p2 CVEser-6p firmware2 CVEser-8-xg2 CVEser-8-xg firmware2 CVEserlite-32 CVEsu6-enterprise2 CVEsu6-enterprise-iw2 CVEsu6-extender2 CVEsu6-iw2 CVEsu6-lite2 CVEsu6-lr2 CVEsu6-mesh2 CVEsu6-pro2 CVEsu6\+2 CVEsuap-ac-iw2 CVEsuap-ac-lite2 CVEsuap-ac-lr2 CVEsuap-ac-m2 CVEsuap-ac-m-pro2 CVEsuap-ac-pro2 CVEsunifi cloud key plus2 CVEsunifi protect firmware2 CVEsunifi uap firmware2 CVEsus-16-150w2 CVEsus-24-250w2 CVEsus-48-500w2 CVEsus-8-150w2 CVEsus-8-60w2 CVEsus-xg-6poe2 CVEsusw-16-poe2 CVEsusw-242 CVEsusw-24-poe2 CVEsusw-482 CVEsusw-48-poe2 CVEsusw-aggregation2 CVEsusw-enterprise-24-poe2 CVEsusw-enterprise-48-poe2 CVEsusw-enterprise-8-poe2 CVEsusw-enterprisexg-242 CVEsusw-flex2 CVEsusw-flex-xg2 CVEsusw-industrial2 CVEsusw-lite-16-poe2 CVEsusw-lite-8-poe2 CVEsusw-mission-critical2 CVEsusw-pro-242 CVEsusw-pro-24-poe2 CVEsusw-pro-482 CVEsusw-pro-48-poe2 CVEsusw-pro-aggregation2 CVEsairfiber 60-xg firmware1 CVEsairfiber 60-xg1 CVEsairfiber 60-lr firmware1 CVEsairfiber 60-lr1 CVEsairfiber 60-hd firmware1 CVEsairfiber 60-hd1 CVEsairfiber 601 CVEsaircube firmware1 CVEsaircube1 CVEsunifi meshing access point firmware1 CVEsaf5x1 CVEsunifi network controller1 CVEsunifi network video recorder1 CVEsunifi os1 CVEsaf5 firmware1 CVEsunifi protect controller1 CVEsusg-pro-4 firmware1 CVEsaf51 CVEsua lite1 CVEsua lite firmware1 CVEsunifi talk1 CVEsusg firmware1 CVEsaf-2x firmware1 CVEsunifi video controller1 CVEsaf-2x1 CVEsusg1 CVEsaircam mini1 CVEsaircam firmware1 CVEsubb-xg firmware1 CVEsubb firmware1 CVEsucrm1 CVEsudb-pro1 CVEsudb-pro-sector1 CVEsudb-pro-sector firmware1 CVEsudb-pro firmware1 CVEsunifi 521 CVEsunifi access1 CVEsunifi cloud key gen21 CVEsunifi cloud key gen2 firmware1 CVEsunifi cloud key gen2 plus1 CVEsunifi cloud key gen2 plus firmware1 CVEsusg-pro-41 CVEsunifi connect application1 CVEsunifi connect ev station lite1 CVEsunifi connect ev station lite firmware1 CVEsaircam dome1 CVEsunifi controller firmware1 CVEsunifi dream machine1 CVEsaf5x firmware1 CVEsunifi dream machine pro firmware1 CVEsunifi dream machine special edition1 CVEsunifi dream router1 CVEsunifi dream wall1 CVEsunifi firmware1 CVEser-8 firmware1 CVEsunifi meshing access point1 CVEserlite-3 firmware1 CVEserpoe-51 CVEserpoe-5 firmware1 CVEserpro-81 CVEserpro-8 firmware1 CVEser-81 CVEser-12p firmware1 CVEser-12p1 CVEser-10x firmware1 CVEser-10x1 CVEsep-r8 firmware1 CVEsep-r81 CVEsep-r6 firmware1 CVEsep-r61 CVEsedgeswitch xp1 CVEsedgemax edgepower 54v firmware1 CVEsedgemax edgepower 54v1 CVEsedgemax edgepower 24v firmware1 CVEsedgemax edgepower 24v1 CVEsedgemax1 CVEsargentina afip invoices1 CVEsairvision firmware1 CVEsairvision controller1 CVEsairmax m xw firmware1 CVEsairmax m xw1 CVEsairmax m xm firmware1 CVEsmfi controller1 CVEsairmax m xm1 CVEsairmax m ti firmware1 CVEsairmax m ti1 CVEsairmax m firmware1 CVEsairgateway firmware1 CVEsairgateway1 CVEsairfiber gigabeam firmware1 CVEsairfiber gigabeam1 CVEsairfiber af60 firmware1 CVEsairfiber af60-xg firmware1 CVEsairfiber af60-xg1 CVEsairfiber af601 CVEsairfiber af24hd firmware1 CVEsairfiber af24hd1 CVEsairfiber af24 firmware1 CVEsairfiber af241 CVEsairfiber 60 firmware1 CVEs

Recent Vulnerabilities

View all 89
CVE-2026-50746CRITICAL 10.0

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

CVE-2026-21639HIGH 8.8

A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.

CVE-2026-21638HIGH 8.8

A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products: UBB-XG (Version 1.2.2 and earlier) UDB-Pro/UDB-Pro-Sector (Version 1.4.1 and earlier) UBB (Version 3.1.5 and earlier) Mitigation: Update your UBB-XG to Version 1.2.3 or later. Update your UDB-Pro/UDB-Pro-Sector to Version 1.4.2 or later. Update your UBB to Version 3.1.7 or later.

CVE-2026-21635MEDIUM 5.3

An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a device that was only adopted via Ethernet.

CVE-2026-21634MEDIUM 6.5

A malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery protocol causing it to restart. Affected Products: UniFi Protect Application (Version 6.1.79 and earlier). Mitigation: Update your UniFi Protect Application to Version 6.2.72 or later.

CVE-2026-21633HIGH 8.8

A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerability in the Unifi Protect Application (Version 6.1.79 and earlier). Affected Products: UniFi Protect Application (Version 6.1.79 and earlier). Mitigation: Update your UniFi Protect Application to Version 6.2.72 or later.

CVE-2025-59467HIGH 7.5

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier) Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.

CVE-2025-52665CRITICAL 10.0

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

CVE-2024-42025HIGH 7.8

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privileges to root on the host device.

CVE-2023-41721MEDIUM 5.3

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later.

CVE-2023-38034CRITICAL 9.8

A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update UniFi Switches to Version 6.5.59 or later.

CVE-2023-35085CRITICAL 9.8

An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update the UniFi Switches to Version 6.5.59 or later.

CVE-2023-31998HIGH 7.5

A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.

CVE-2023-32000MEDIUM 4.8

A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit a malicious web page.

CVE-2023-31997CRITICAL 9.0

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.

CVE-2023-28365CRITICAL 9.1

A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.

CVE-2023-2379HIGH 7.5

A vulnerability classified as critical has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown part of the component Web Service. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227655.

CVE-2023-2378MEDIUM 6.3

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation of the argument suffix-rate-up leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227654 is the identifier assigned to this vulnerability.

CVE-2023-2377MEDIUM 6.3

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Web Management Interface. The manipulation of the argument name leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227653 was assigned to this vulnerability.

CVE-2023-2376MEDIUM 6.3

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. It has been classified as critical. Affected is an unknown function of the component Web Management Interface. The manipulation of the argument dpi leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227652.

CVE-2023-2375MEDIUM 6.3

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6 and classified as critical. This issue affects some unknown processing of the component Web Management Interface. The manipulation of the argument src leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227651.

CVE-2023-2374MEDIUM 6.3

A vulnerability has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6 and classified as critical. This vulnerability affects unknown code of the component Web Management Interface. The manipulation of the argument ecn-down leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227650 is the identifier assigned to this vulnerability.

CVE-2023-2373MEDIUM 6.3

A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown part of the component Web Management Interface. The manipulation of the argument ecn-up leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227649 was assigned to this vulnerability.

CVE-2023-28124MEDIUM 5.5

Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Version 0.62.3 and later.

CVE-2023-28123MEDIUM 5.5

A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later.

ui — Vendor | Dragons Community