VYPR

Unifi Protect

by UI

CVEs (11)

  • CVE-2021-22943CriAug 31, 2021
    risk 0.62cvss 9.6epss 0.00

    A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vulnerability is fixed in UniFi Protect application V1.19.0…

  • CVE-2026-21633HigJan 5, 2026
    risk 0.57cvss 8.8epss 0.00

    A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerability in the Unifi Protect Application (Version 6.1.79 and earlier). Affected Products: UniFi Protect…

  • CVE-2021-22957HigNov 24, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in…

  • CVE-2021-22944HigAug 31, 2021
    risk 0.52cvss 8.0epss 0.00

    A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role and network access to gain the same privileges as the owner of the UniFi Protect application. This vulnerability is fixed in UniFi Protect application V1.19.0…

  • CVE-2026-21634MedJan 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery protocol causing it to restart. Affected Products: UniFi Protect Application (Version 6.1.79 and earlier). Mitigation: Update…

  • CVE-2020-8213MedJul 30, 2020
    risk 0.35cvss 5.3epss 0.01

    An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP response code and response timing.

  • CVE-2026-56841HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.

  • CVE-2026-55115CriJul 2, 2026
    risk 0.00cvss 9.9epss 0.01

    A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

  • CVE-2026-54409HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.

  • CVE-2026-54408HigJul 2, 2026
    risk 0.00cvss 8.6epss 0.00

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.

  • CVE-2026-54407HigJul 2, 2026
    risk 0.00cvss 8.6epss 0.00

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.