Skip to content
Noroxi

hackerbay records

23 published records for vendor hackerbay.

All records

23 records
  • OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe

    CriticalCVSS 9.9No exploitEPSS 1%

    hackerbay · oneuptimeMar 26, 2026

  • OneUptime Synthetic Monitor RCE via exposed Playwright browser object

    CriticalCVSS 9.9No exploitEPSS 1%

    hackerbay · oneuptimeMar 10, 2026

  • OneUptime ClickHouse SQL Injection via Aggregate Query Parameters

    CriticalCVSS 9.9No exploitEPSS 1%

    hackerbay · oneuptimeMar 13, 2026

  • OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE

    CriticalCVSS 9.9Proof of conceptEPSS 1%

    hackerbay · oneuptimeFeb 21, 2026

  • OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE

    CriticalCVSS 9.9No exploitEPSS 1%

    hackerbay · oneuptimeMar 10, 2026

  • OneUptime Synthetic Monitor RCE via exposed Playwright browser object

    CriticalCVSS 9.9No exploitEPSS 1%

    hackerbay · oneuptimeMar 10, 2026

  • OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header

    CriticalCVSS 9.9No exploitEPSS 0%

    hackerbay · oneuptimeMar 10, 2026

  • OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()

    HighCVSS 8.8No exploitEPSS 3%

    hackerbay · oneuptimeFeb 25, 2026

  • OneUptime: Unauthenticated Workflow Execution via ManualAPI

    CriticalCVSS 9.2No exploitEPSS 1%

    hackerbay · oneuptimeApr 2, 2026

  • OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure

    CriticalCVSS 9.2No exploitEPSS 1%

    hackerbay · oneuptimeApr 2, 2026

  • OneUptime: Missing Authentication on Notification Endpoints

    CriticalCVSS 9.1No exploitEPSS 0%

    hackerbay · oneuptimeApr 2, 2026

  • OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay

    CriticalCVSS 9.0No exploitEPSS 0%

    hackerbay · oneuptimeMar 6, 2026

  • OneUptime Unauthorized User Creation via API

    HighCVSS 8.8No exploitEPSS 0%

    hackerbay · oneuptimeNov 26, 2025

  • OneUptime: Path Traversal — Arbitrary File Read (No Auth)

    HighCVSS 8.6Proof of conceptEPSS 1%

    hackerbay · oneuptimeMar 10, 2026

  • OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding

    HighCVSS 8.6No exploitEPSS 0%

    hackerbay · oneuptimeMar 10, 2026

  • OneUptime: WhatsApp Webhook Missing Signature Verification

    HighCVSS 8.7No exploitEPSS 0%

    hackerbay · oneuptimeMar 20, 2026

  • OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation

    HighCVSS 8.3No exploitEPSS 1%

    hackerbay · oneuptimeMar 24, 2024

  • OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters

    HighCVSS 8.1No exploitEPSS 0%

    hackerbay · oneuptimeMar 20, 2026

  • OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verification

    HighCVSS 8.1No exploitEPSS 0%

    hackerbay · oneuptimeApr 2, 2026

  • OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")

    HighCVSS 7.6No exploitEPSS 0%

    hackerbay · oneuptimeMar 13, 2026

  • OneUptime: Password Reset Token Logged at INFO Level

    MediumCVSS 6.9No exploitEPSS 0%

    hackerbay · oneuptimeMar 13, 2026

  • OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

    MediumCVSS 6.9No exploitEPSS 0%

    hackerbay · oneuptimeNov 26, 2025

  • OneUptime has WhatsApp Resend Verification Authorization Bypass

    MediumCVSS 5.3No exploitEPSS 0%

    hackerbay · oneuptimeMar 10, 2026