threat
engine
.sh
Back
·
··:··
Home
/
Product
/
hackerbay oneuptime
Product
hackerbay oneuptime
23 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-35053
< 10.0.42
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI expose
9.8
CRITICAL
CVE-2026-34840
< 10.0.42
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (
8.1
HIGH
CVE-2026-34759
< 10.0.42
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints a
8.1
HIGH
CVE-2026-34758
< 10.0.40
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notificatio
9.1
CRITICAL
CVE-2026-33396
< 10.0.35
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (
9.9
CRITICAL
CVE-2026-33143
< 10.0.34
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (
7.5
HIGH
CVE-2026-33142
< 10.0.34
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHo
8.1
HIGH
CVE-2026-32598
< 10.0.24
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete p
6.5
MEDIUM
CVE-2026-32308
< 10.0.23
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Merma
7.6
HIGH
CVE-2026-32306
< 10.0.23
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-
9.9
CRITICAL
CVE-2026-30959
< 10.0.21
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticate
5.0
MEDIUM
CVE-2026-30958
< 10.0.21
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /w
7.2
HIGH
CVE-2026-30957
< 10.0.21
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-pr
9.9
CRITICAL
CVE-2026-30956
< 10.0.21
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authoriz
9.9
CRITICAL
CVE-2026-30921
< 10.0.20
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-priv
9.9
CRITICAL
CVE-2026-30920
< 10.0.19
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts atta
8.6
HIGH
CVE-2026-30887
< 10.0.18
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run cus
9.9
CRITICAL
CVE-2026-28787
<= 10.0.11
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication imp
8.2
HIGH
CVE-2026-27728
< 10.0.7
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerabilit
9.9
CRITICAL
CVE-2026-27574
< 10.0.5
OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor featu
9.9
CRITICAL
CVE-2025-66028
< 8.0.5567
OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privile
8.2
HIGH
CVE-2025-65966
all versions
OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new acc
8.1
HIGH
CVE-2024-29194
>= 7.0.1803 and < 7.0.1815
OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-s
8.3
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin