hackerbay has 14 CVEs on record. The busiest recent month was March 2026 with 10. The median CVSS is 8.1 (high), with 6 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-862 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2026-33396Critical· 9.9OneUptime is an open-source monitoring and observability platform55CVE-2026-32306Critical· 9.9OneUptime is a solution for monitoring and managing online services55CVE-2026-30957Critical· 9.9OneUptime is a solution for monitoring and managing online services55CVE-2026-30956Critical· 9.9OneUptime is a solution for monitoring and managing online services55CVE-2026-35053Critical· 9.8OneUptime is an open-source monitoring and observability platform54
hackerbay vulnerabilities
CVEs affecting hackerbay, newest first. Open any entry for full detail, references, and exploit status.
14 CVEsRSS
CVE-2026-35053Critical· 9.8OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflo…
CVE-2026-34840High· 8.1OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity extraction. isSigna…
CVE-2026-34759High· 8.1OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use…
CVE-2026-34758Critical· 9.1OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase…
CVE-2026-33396Critical· 9.9OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monito…
CVE-2026-33143High· 7.5OneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp…
CVE-2026-33142High· 8.1OneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the _aggregateBy method b…
CVE-2026-32598Medium· 6.5OneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default i…
CVE-2026-32308High· 7.6OneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This configuration explic…
CVE-2026-32306Critical· 9.9OneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpol…
CVE-2026-30959Medium· 5.0OneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated …
CVE-2026-30958High· 7.2PoCOneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The compone…
CVE-2026-30957Critical· 9.9OneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. …
CVE-2026-30956Critical· 9.9OneUptime is a solution for monitoring and managing online services
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header…