hackerbay kayıtları
hackerbay üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %91,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-285 Improper Authorization3
- CWE-749 Exposed Dangerous Method or Function2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-306 Missing Authentication for Critical Function2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-33396İstismar yok | OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probehackerbay · oneuptime · CWE-78 | Kritik9,9 | — | %1,2 | 26 Mar 2026 |
39İzleyin | CVE-2026-30957İstismar yok | OneUptime Synthetic Monitor RCE via exposed Playwright browser objecthackerbay · oneuptime · CWE-749 | Kritik9,9 | — | %1,1 | 10 Mar 2026 |
39İzleyin | CVE-2026-32306İstismar yok | OneUptime ClickHouse SQL Injection via Aggregate Query Parametershackerbay · oneuptime · CWE-89 | Kritik9,9 | — | %0,9 | 13 Mar 2026 |
39İzleyin | CVE-2026-27574Kavram kanıtı | OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCEhackerbay · oneuptime · CWE-94 | Kritik9,9 | — | %0,6 | 21 Şub 2026 |
39İzleyin | CVE-2026-30887İstismar yok | OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCEhackerbay · oneuptime · CWE-94 | Kritik9,9 | — | %0,6 | 10 Mar 2026 |
39İzleyin | CVE-2026-30921İstismar yok | OneUptime Synthetic Monitor RCE via exposed Playwright browser objecthackerbay · oneuptime · CWE-749 | Kritik9,9 | — | %0,5 | 10 Mar 2026 |
39İzleyin | CVE-2026-30956İstismar yok | OneUptime has authorization bypass via client‑controlled is-multi-tenant-query headerhackerbay · oneuptime · CWE-285 | Kritik9,9 | — | %0,5 | 10 Mar 2026 |
36İzleyin | CVE-2026-27728İstismar yok | OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()hackerbay · oneuptime · CWE-78 | Yüksek8,8 | — | %2,5 | 25 Şub 2026 |
36İzleyin | CVE-2026-35053İstismar yok | OneUptime: Unauthenticated Workflow Execution via ManualAPIhackerbay · oneuptime · CWE-306 | Kritik9,2 | — | %0,8 | 2 Nis 2026 |
36İzleyin | CVE-2026-34759İstismar yok | OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposurehackerbay · oneuptime · CWE-862 | Kritik9,2 | — | %0,7 | 2 Nis 2026 |
36İzleyin | CVE-2026-34758İstismar yok | OneUptime: Missing Authentication on Notification Endpointshackerbay · oneuptime · CWE-306 | Kritik9,1 | — | %0,5 | 2 Nis 2026 |
36İzleyin | CVE-2026-28787İstismar yok | OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replayhackerbay · oneuptime · CWE-287 | Kritik9,0 | — | %0,4 | 6 Mar 2026 |
35İzleyin | CVE-2025-65966İstismar yok | OneUptime Unauthorized User Creation via APIhackerbay · oneuptime · CWE-285 | Yüksek8,8 | — | %0,3 | 26 Kas 2025 |
34İzleyin | CVE-2026-30958Kavram kanıtı | OneUptime: Path Traversal — Arbitrary File Read (No Auth)hackerbay · oneuptime · CWE-22 | Yüksek8,6 | — | %1,2 | 10 Mar 2026 |
34İzleyin | CVE-2026-30920İstismar yok | OneUptime has broken access control in GitHub App installation flow that allows unauthorized project bindinghackerbay · oneuptime · CWE-345 | Yüksek8,6 | — | %0,2 | 10 Mar 2026 |
34İzleyin | CVE-2026-33143İstismar yok | OneUptime: WhatsApp Webhook Missing Signature Verificationhackerbay · oneuptime · CWE-345 | Yüksek8,7 | — | %0,2 | 20 Mar 2026 |
33İzleyin | CVE-2024-29194İstismar yok | OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulationhackerbay · oneuptime · CWE-639 | Yüksek8,3 | — | %0,7 | 24 Mar 2024 |
32İzleyin | CVE-2026-33142İstismar yok | OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parametershackerbay · oneuptime · CWE-89 | Yüksek8,1 | — | %0,4 | 20 Mar 2026 |
32İzleyin | CVE-2026-34840İstismar yok | OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verificationhackerbay · oneuptime · CWE-347 | Yüksek8,1 | — | %0,3 | 2 Nis 2026 |
30İzleyin | CVE-2026-32308İstismar yok | OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")hackerbay · oneuptime · CWE-79 | Yüksek7,6 | — | %0,3 | 13 Mar 2026 |
27İzleyin | CVE-2026-32598İstismar yok | OneUptime: Password Reset Token Logged at INFO Levelhackerbay · oneuptime · CWE-532 | Orta6,9 | — | %0,3 | 13 Mar 2026 |
27İzleyin | CVE-2025-66028İstismar yok | OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulationhackerbay · oneuptime · CWE-284 | Orta6,9 | — | %0,3 | 26 Kas 2025 |
21İzleyin | CVE-2026-30959İstismar yok | OneUptime has WhatsApp Resend Verification Authorization Bypasshackerbay · oneuptime · CWE-285 | Orta5,3 | — | %0,4 | 10 Mar 2026 |
- CVE-2026-3339639İzleyin
OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
KritikCVSS 9,9İstismar yokEPSS %1hackerbay · oneuptime26 Mar 2026
- CVE-2026-3095739İzleyin
OneUptime Synthetic Monitor RCE via exposed Playwright browser object
KritikCVSS 9,9İstismar yokEPSS %1hackerbay · oneuptime10 Mar 2026
- CVE-2026-3230639İzleyin
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
KritikCVSS 9,9İstismar yokEPSS %1hackerbay · oneuptime13 Mar 2026
- CVE-2026-2757439İzleyin
OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE
KritikCVSS 9,9Kavram kanıtıEPSS %1hackerbay · oneuptime21 Şub 2026
- CVE-2026-3088739İzleyin
OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE
KritikCVSS 9,9İstismar yokEPSS %1hackerbay · oneuptime10 Mar 2026
- CVE-2026-3092139İzleyin
OneUptime Synthetic Monitor RCE via exposed Playwright browser object
KritikCVSS 9,9İstismar yokEPSS %1hackerbay · oneuptime10 Mar 2026
- CVE-2026-3095639İzleyin
OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header
KritikCVSS 9,9İstismar yokEPSS %0hackerbay · oneuptime10 Mar 2026
- CVE-2026-2772836İzleyin
OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()
YüksekCVSS 8,8İstismar yokEPSS %3hackerbay · oneuptime25 Şub 2026
- CVE-2026-3505336İzleyin
OneUptime: Unauthenticated Workflow Execution via ManualAPI
KritikCVSS 9,2İstismar yokEPSS %1hackerbay · oneuptime2 Nis 2026
- CVE-2026-3475936İzleyin
OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure
KritikCVSS 9,2İstismar yokEPSS %1hackerbay · oneuptime2 Nis 2026
- CVE-2026-3475836İzleyin
OneUptime: Missing Authentication on Notification Endpoints
KritikCVSS 9,1İstismar yokEPSS %0hackerbay · oneuptime2 Nis 2026
- CVE-2026-2878736İzleyin
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
KritikCVSS 9,0İstismar yokEPSS %0hackerbay · oneuptime6 Mar 2026
- CVE-2025-6596635İzleyin
OneUptime Unauthorized User Creation via API
YüksekCVSS 8,8İstismar yokEPSS %0hackerbay · oneuptime26 Kas 2025
- CVE-2026-3095834İzleyin
OneUptime: Path Traversal — Arbitrary File Read (No Auth)
YüksekCVSS 8,6Kavram kanıtıEPSS %1hackerbay · oneuptime10 Mar 2026
- CVE-2026-3092034İzleyin
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
YüksekCVSS 8,6İstismar yokEPSS %0hackerbay · oneuptime10 Mar 2026
- CVE-2026-3314334İzleyin
OneUptime: WhatsApp Webhook Missing Signature Verification
YüksekCVSS 8,7İstismar yokEPSS %0hackerbay · oneuptime20 Mar 2026
- CVE-2024-2919433İzleyin
OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation
YüksekCVSS 8,3İstismar yokEPSS %1hackerbay · oneuptime24 Mar 2024
- CVE-2026-3314232İzleyin
OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters
YüksekCVSS 8,1İstismar yokEPSS %0hackerbay · oneuptime20 Mar 2026
- CVE-2026-3484032İzleyin
OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verification
YüksekCVSS 8,1İstismar yokEPSS %0hackerbay · oneuptime2 Nis 2026
- CVE-2026-3230830İzleyin
OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")
YüksekCVSS 7,6İstismar yokEPSS %0hackerbay · oneuptime13 Mar 2026
- CVE-2026-3259827İzleyin
OneUptime: Password Reset Token Logged at INFO Level
OrtaCVSS 6,9İstismar yokEPSS %0hackerbay · oneuptime13 Mar 2026
- CVE-2025-6602827İzleyin
OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
OrtaCVSS 6,9İstismar yokEPSS %0hackerbay · oneuptime26 Kas 2025
- CVE-2026-3095921İzleyin
OneUptime has WhatsApp Resend Verification Authorization Bypass
OrtaCVSS 5,3İstismar yokEPSS %0hackerbay · oneuptime10 Mar 2026