VYPR

Vendor CVEs

Unify

All CVEs

77 total · sorted by risk
  • CVE-2026-21634MedJan 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery protocol causing it to restart. Affected Products: UniFi Protect Application (Version 6.1.79 and earlier). Mitigation: Update…

  • CVE-2023-28361MedMay 11, 2023
    risk 0.42cvss 6.5epss 0.00

    A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR…

  • CVE-2021-44527MedDec 7, 2021
    risk 0.42cvss 6.5epss 0.00

    A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gained access to the network to perform a Deny of Service (DoS) attack on the affected switch.This vulnerability is fixed in UniFi Switch firmware 5.76.6 and later.

  • CVE-2020-8145MedApr 1, 2020
    risk 0.42cvss 6.5epss 0.01

    The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access these…

  • CVE-2023-40262MedFeb 8, 2024
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration component via Access Request.

  • CVE-2013-3572MedDec 31, 2013
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname.

  • CVE-2015-8251MedSep 25, 2017
    risk 0.38cvss 5.9epss 0.01

    OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phone IP 35G Eco SIP V3, OpenStage 60 and OpenScape Desk Phone IP 55G HFA V3, OpenStage 15, 20E, 20, and 40 and OpenScape Desk Phone IP 35G…

  • CVE-2020-8148MedApr 13, 2020
    risk 0.35cvss 5.3epss 0.01

    UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicious API request. This affects Cloud Key gen2 and Cloud Key gen2 Plus.

  • CVE-2024-37380MedJul 22, 2024
    risk 0.34cvss 5.3epss 0.00

    A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi U6+ Access Point (Version 6.6.65 and earlier) Mitigation: Update your UniFi U6+ Access Point to Version 6.6.74 or…

  • CVE-2023-41721MedOct 25, 2023
    risk 0.34cvss 5.3epss 0.01

    Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with…

  • CVE-2025-27213MedAug 21, 2025
    risk 0.32cvss 4.9epss 0.00

    An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and…

  • CVE-2014-9563MedApr 12, 2018
    risk 0.32cvss 4.9epss 0.01

    CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allows remote authenticated users to modify the root password and consequently access the debug port using the…

  • CVE-2023-40264MedFeb 8, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.

  • CVE-2024-29208LowMay 7, 2024
    risk 0.14cvss 2.2epss 0.00

    An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version…

  • CVE-2024-29206LowMay 7, 2024
    risk 0.14cvss 2.2epss 0.00

    An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro…

  • CVE-2000-1025Dec 11, 2000
    risk 0.04cvss —epss 0.08

    eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.

  • CVE-2000-1114Jan 9, 2001
    risk 0.03cvss —epss 0.03

    Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".

  • CVE-2026-56842HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.

  • CVE-2026-56841HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.

  • CVE-2026-55119HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.

  • CVE-2026-55118HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

  • CVE-2026-55115CriJul 2, 2026
    risk 0.00cvss 9.9epss 0.00

    A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

  • CVE-2026-55114HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

  • CVE-2026-54409HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.

  • CVE-2026-54407HigJul 2, 2026
    risk 0.00cvss 8.6epss 0.00

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

  • CVE-2026-50746CriJul 2, 2026
    risk 0.00cvss 10.0epss 0.02

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

  • CVE-2000-1024Dec 11, 2000
    risk 0.00cvss —epss 0.05

    eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.

Page 2 of 2