Hackerbay
Hackerbay Oneuptime: vulnerabilidades y CVE
Hackerbay Oneuptime tiene 25 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses24
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-80350 | Alta (7.1) | 0.40% | — | 26 ago 2026 | OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls… |
| CVE-2026-45102 | Crítica (9.9) | 0.48% | — | 27 may 2026 | OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive. This API was not designed for that and can be escaped via error… |
| CVE-2026-35053 | Crítica (9.2) | 0.82% | — | 2 abr 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST… |
| CVE-2026-34840 | Alta (8.1) | 0.34% | — | 2 abr 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity… |
| CVE-2026-34759 | Crítica (9.2) | 0.67% | — | 2 abr 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same… |
| CVE-2026-34758 | Crítica (9.1) | 0.50% | — | 2 abr 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and… |
| CVE-2026-33396 | Crítica (9.9) | 1.1% | — | 26 mar 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by… |
| CVE-2026-33143 | Alta (8.7) | 0.20% | — | 20 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying… |
| CVE-2026-33142 | Alta (8.1) | 0.39% | — | 20 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the… |
| CVE-2026-32598 | Media (6.9) | 0.32% | — | 13 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is… |
| CVE-2026-32308 | Alta (7.6) | 0.30% | — | 13 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This… |
| CVE-2026-32306 | Crítica (9.9) | 0.91% | — | 13 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName… |
| CVE-2026-30959 | Media (5.3) | 0.35% | — | 10 mar 2026 | OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership… |
| CVE-2026-30958 | Alta (8.6) | 1.2% | — | 10 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server… |
| CVE-2026-30957 | Crítica (9.9) | 1.1% | — | 10 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe… |
| CVE-2026-30956 | Crítica (9.9) | 0.47% | — | 10 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged… |
| CVE-2026-30921 | Crítica (9.9) | 0.52% | — | 10 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the… |
| CVE-2026-30920 | Alta (8.6) | 0.22% | — | 10 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates… |
| CVE-2026-30887 | Crítica (9.9) | 0.56% | — | 10 mar 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the… |
| CVE-2026-28787 | Crítica (9) | 0.38% | — | 6 mar 2026 | OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is… |
| CVE-2026-27728 | Alta (8.8) | 2.5% | — | 25 feb 2026 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to… |
| CVE-2026-27574 | Crítica (9.9) | 0.62% | — | 21 feb 2026 | OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to… |
| CVE-2025-66028 | Media (6.9) | 0.30% | — | 26 nov 2025 | OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server… |
| CVE-2025-65966 | Alta (8.8) | 0.31% | — | 26 nov 2025 | OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface.… |
| CVE-2024-29194 | Alta (8.3) | 0.70% | — | 24 mar 2024 | OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Specifically, the is_master_admin key, stored… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.