CVEs we hold for Oneuptime
Records whose assigning authority named Oneuptime as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-80350OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URLOneUptime
CVE-2026-45102OneUptime: RCE due to Node.js' vm module escape via error objects and infinite recursiononeuptime
CVE-2026-34840OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verificationoneuptime
CVE-2026-34759OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption…oneuptime
CVE-2026-33396OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary…oneuptime
CVE-2026-33142OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parametersoneuptime
CVE-2026-30956OneUptime has authorization bypass via client‑controlled is-multi-tenant-query headeroneuptime
CVE-2026-30920OneUptime has broken access control in GitHub App installation flow that allows unauthorized project bindingoneuptime
CVE-2026-30887OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCEoneuptime
CVE-2026-28787OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing…oneuptime
CVE-2026-27728OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()oneuptime
CVE-2026-27574OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCEoneuptime
CVE-2025-66028OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulationoneuptime
CVE-2024-29194OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulationoneuptime
25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.