VYPR

Vendor CVEs

Hackerbay

All CVEs

23 total · sorted by risk
  • CVE-2026-30957CriMar 10, 2026
    risk 0.64cvss 9.9epss 0.01

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. The root cause is that untrusted Synthetic…

  • CVE-2026-30956CriMar 10, 2026
    risk 0.64cvss 9.9epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header together with a controlled projectid…

  • CVE-2026-30921CriMar 10, 2026
    risk 0.64cvss 9.9epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service. In the current implementation, this untrusted…

  • CVE-2026-30887CriMar 10, 2026
    risk 0.64cvss 9.9epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this untrusted user code inside the insecure…

  • CVE-2026-35053CriApr 2, 2026
    risk 0.57cvss 9.8epss 0.01

    OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication…

  • CVE-2026-33396CriMar 26, 2026
    risk 0.57cvss 9.9epss 0.01

    OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. Synthetic…

  • CVE-2026-32306CriMar 13, 2026
    risk 0.57cvss 9.9epss 0.01

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpolates them directly into ClickHouse SQL…

  • CVE-2026-27728CriFeb 25, 2026
    risk 0.57cvss 9.9epss 0.02

    OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe…

  • CVE-2026-27574CriFeb 21, 2026
    risk 0.57cvss 9.9epss 0.01

    OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape…

  • CVE-2026-30920HigMar 10, 2026
    risk 0.56cvss 8.6epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is…

  • CVE-2026-28787HigMar 6, 2026
    risk 0.53cvss 8.2epss 0.00

    OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client…

  • CVE-2026-34758CriApr 2, 2026
    risk 0.52cvss 9.1epss 0.00

    OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version…

  • CVE-2026-30958HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.01

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated…

  • CVE-2024-29194HigMar 24, 2024
    risk 0.47cvss 8.3epss 0.01

    OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Specifically, the is_master_admin key, stored in the local storage of the browser, can be manipulated by…

  • CVE-2026-34840HigApr 2, 2026
    risk 0.46cvss 8.1epss 0.00

    OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity extraction. isSignatureValid() verifies the first …

  • CVE-2026-34759HigApr 2, 2026
    risk 0.46cvss 8.1epss 0.01

    OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use ClusterKeyAuthorization.isAuthorizedServic…

  • CVE-2026-33142HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the _aggregateBy method but did not apply the same validation to…

  • CVE-2025-66028HigNov 26, 2025
    risk 0.46cvss 8.2epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMasterAdmin. By…

  • CVE-2025-65966HigNov 26, 2025
    risk 0.46cvss 8.1epss 0.00

    OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0.

  • CVE-2026-33143HigMar 20, 2026
    risk 0.42cvss 7.5epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature,…

  • CVE-2026-32308HigMar 13, 2026
    risk 0.42cvss 7.6epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This configuration explicitly allows interactive event bindings in…

  • CVE-2026-32598MedMar 13, 2026
    risk 0.35cvss 6.5epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to…

  • CVE-2026-30959MedMar 10, 2026
    risk 0.33cvss 5.0epss 0.00

    OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects…