hackerbay records
23 published records for vendor hackerbay.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 91.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-285 Improper Authorization3
- CWE-749 Exposed Dangerous Method or Function2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-306 Missing Authentication for Critical Function2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-33396No exploit | OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probehackerbay · oneuptime · CWE-78 | Critical9.9 | — | 1.2% | Mar 26, 2026 |
39Monitor | CVE-2026-30957No exploit | OneUptime Synthetic Monitor RCE via exposed Playwright browser objecthackerbay · oneuptime · CWE-749 | Critical9.9 | — | 1.1% | Mar 10, 2026 |
39Monitor | CVE-2026-32306No exploit | OneUptime ClickHouse SQL Injection via Aggregate Query Parametershackerbay · oneuptime · CWE-89 | Critical9.9 | — | 0.9% | Mar 13, 2026 |
39Monitor | CVE-2026-27574Proof of concept | OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCEhackerbay · oneuptime · CWE-94 | Critical9.9 | — | 0.6% | Feb 21, 2026 |
39Monitor | CVE-2026-30887No exploit | OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCEhackerbay · oneuptime · CWE-94 | Critical9.9 | — | 0.6% | Mar 10, 2026 |
39Monitor | CVE-2026-30921No exploit | OneUptime Synthetic Monitor RCE via exposed Playwright browser objecthackerbay · oneuptime · CWE-749 | Critical9.9 | — | 0.5% | Mar 10, 2026 |
39Monitor | CVE-2026-30956No exploit | OneUptime has authorization bypass via client‑controlled is-multi-tenant-query headerhackerbay · oneuptime · CWE-285 | Critical9.9 | — | 0.5% | Mar 10, 2026 |
36Monitor | CVE-2026-27728No exploit | OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()hackerbay · oneuptime · CWE-78 | High8.8 | — | 2.5% | Feb 25, 2026 |
36Monitor | CVE-2026-35053No exploit | OneUptime: Unauthenticated Workflow Execution via ManualAPIhackerbay · oneuptime · CWE-306 | Critical9.2 | — | 0.8% | Apr 2, 2026 |
36Monitor | CVE-2026-34759No exploit | OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposurehackerbay · oneuptime · CWE-862 | Critical9.2 | — | 0.7% | Apr 2, 2026 |
36Monitor | CVE-2026-34758No exploit | OneUptime: Missing Authentication on Notification Endpointshackerbay · oneuptime · CWE-306 | Critical9.1 | — | 0.5% | Apr 2, 2026 |
36Monitor | CVE-2026-28787No exploit | OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replayhackerbay · oneuptime · CWE-287 | Critical9.0 | — | 0.4% | Mar 6, 2026 |
35Monitor | CVE-2025-65966No exploit | OneUptime Unauthorized User Creation via APIhackerbay · oneuptime · CWE-285 | High8.8 | — | 0.3% | Nov 26, 2025 |
34Monitor | CVE-2026-30958Proof of concept | OneUptime: Path Traversal — Arbitrary File Read (No Auth)hackerbay · oneuptime · CWE-22 | High8.6 | — | 1.2% | Mar 10, 2026 |
34Monitor | CVE-2026-30920No exploit | OneUptime has broken access control in GitHub App installation flow that allows unauthorized project bindinghackerbay · oneuptime · CWE-345 | High8.6 | — | 0.2% | Mar 10, 2026 |
34Monitor | CVE-2026-33143No exploit | OneUptime: WhatsApp Webhook Missing Signature Verificationhackerbay · oneuptime · CWE-345 | High8.7 | — | 0.2% | Mar 20, 2026 |
33Monitor | CVE-2024-29194No exploit | OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulationhackerbay · oneuptime · CWE-639 | High8.3 | — | 0.7% | Mar 24, 2024 |
32Monitor | CVE-2026-33142No exploit | OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parametershackerbay · oneuptime · CWE-89 | High8.1 | — | 0.4% | Mar 20, 2026 |
32Monitor | CVE-2026-34840No exploit | OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verificationhackerbay · oneuptime · CWE-347 | High8.1 | — | 0.3% | Apr 2, 2026 |
30Monitor | CVE-2026-32308No exploit | OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")hackerbay · oneuptime · CWE-79 | High7.6 | — | 0.3% | Mar 13, 2026 |
27Monitor | CVE-2026-32598No exploit | OneUptime: Password Reset Token Logged at INFO Levelhackerbay · oneuptime · CWE-532 | Medium6.9 | — | 0.3% | Mar 13, 2026 |
27Monitor | CVE-2025-66028No exploit | OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulationhackerbay · oneuptime · CWE-284 | Medium6.9 | — | 0.3% | Nov 26, 2025 |
21Monitor | CVE-2026-30959No exploit | OneUptime has WhatsApp Resend Verification Authorization Bypasshackerbay · oneuptime · CWE-285 | Medium5.3 | — | 0.4% | Mar 10, 2026 |
- CVE-2026-3339639Monitor
OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
CriticalCVSS 9.9No exploitEPSS 1%hackerbay · oneuptimeMar 26, 2026
- CVE-2026-3095739Monitor
OneUptime Synthetic Monitor RCE via exposed Playwright browser object
CriticalCVSS 9.9No exploitEPSS 1%hackerbay · oneuptimeMar 10, 2026
- CVE-2026-3230639Monitor
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
CriticalCVSS 9.9No exploitEPSS 1%hackerbay · oneuptimeMar 13, 2026
- CVE-2026-2757439Monitor
OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE
CriticalCVSS 9.9Proof of conceptEPSS 1%hackerbay · oneuptimeFeb 21, 2026
- CVE-2026-3088739Monitor
OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE
CriticalCVSS 9.9No exploitEPSS 1%hackerbay · oneuptimeMar 10, 2026
- CVE-2026-3092139Monitor
OneUptime Synthetic Monitor RCE via exposed Playwright browser object
CriticalCVSS 9.9No exploitEPSS 1%hackerbay · oneuptimeMar 10, 2026
- CVE-2026-3095639Monitor
OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header
CriticalCVSS 9.9No exploitEPSS 0%hackerbay · oneuptimeMar 10, 2026
- CVE-2026-2772836Monitor
OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()
HighCVSS 8.8No exploitEPSS 3%hackerbay · oneuptimeFeb 25, 2026
- CVE-2026-3505336Monitor
OneUptime: Unauthenticated Workflow Execution via ManualAPI
CriticalCVSS 9.2No exploitEPSS 1%hackerbay · oneuptimeApr 2, 2026
- CVE-2026-3475936Monitor
OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure
CriticalCVSS 9.2No exploitEPSS 1%hackerbay · oneuptimeApr 2, 2026
- CVE-2026-3475836Monitor
OneUptime: Missing Authentication on Notification Endpoints
CriticalCVSS 9.1No exploitEPSS 0%hackerbay · oneuptimeApr 2, 2026
- CVE-2026-2878736Monitor
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
CriticalCVSS 9.0No exploitEPSS 0%hackerbay · oneuptimeMar 6, 2026
- CVE-2025-6596635Monitor
OneUptime Unauthorized User Creation via API
HighCVSS 8.8No exploitEPSS 0%hackerbay · oneuptimeNov 26, 2025
- CVE-2026-3095834Monitor
OneUptime: Path Traversal — Arbitrary File Read (No Auth)
HighCVSS 8.6Proof of conceptEPSS 1%hackerbay · oneuptimeMar 10, 2026
- CVE-2026-3092034Monitor
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
HighCVSS 8.6No exploitEPSS 0%hackerbay · oneuptimeMar 10, 2026
- CVE-2026-3314334Monitor
OneUptime: WhatsApp Webhook Missing Signature Verification
HighCVSS 8.7No exploitEPSS 0%hackerbay · oneuptimeMar 20, 2026
- CVE-2024-2919433Monitor
OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation
HighCVSS 8.3No exploitEPSS 1%hackerbay · oneuptimeMar 24, 2024
- CVE-2026-3314232Monitor
OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters
HighCVSS 8.1No exploitEPSS 0%hackerbay · oneuptimeMar 20, 2026
- CVE-2026-3484032Monitor
OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verification
HighCVSS 8.1No exploitEPSS 0%hackerbay · oneuptimeApr 2, 2026
- CVE-2026-3230830Monitor
OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")
HighCVSS 7.6No exploitEPSS 0%hackerbay · oneuptimeMar 13, 2026
- CVE-2026-3259827Monitor
OneUptime: Password Reset Token Logged at INFO Level
MediumCVSS 6.9No exploitEPSS 0%hackerbay · oneuptimeMar 13, 2026
- CVE-2025-6602827Monitor
OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
MediumCVSS 6.9No exploitEPSS 0%hackerbay · oneuptimeNov 26, 2025
- CVE-2026-3095921Monitor
OneUptime has WhatsApp Resend Verification Authorization Bypass
MediumCVSS 5.3No exploitEPSS 0%hackerbay · oneuptimeMar 10, 2026