15 Total CVEs
15 AI Analyzed
0 CISA KEV
10 Critical

Profile

0% ended up actively exploited 0 of 15 added to CISA KEV
67% rated critical (CVSS 9.0+) 10 critical, 5 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

15 CVEs in the last 12 months

Products

  • OneUptime7
  • OneUptime Synthetic Monitors3
  • App callback1

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-45102
Analyzed
9.9
OneUptime OneUptime

OneUptime is vulnerable to a sandbox escape in its Node.js environment due to the improper use of the vm module.

2026-05-28
CVE-2026-34840
Analyzed
8.1
OneUptime Multiple Products

OneUptime is an open-source monitoring and observability platform

2026-04-03
CVE-2026-34758
Analyzed
9.1
OneUptime OneUptime

Unauthenticated access to notification and phone management endpoints in OneUptime allows attackers to abuse communication services and perform unauth...

2026-04-03
CVE-2026-33396
Analyzed
9.9
OneUptime OneUptime

OneUptime versions prior to 10.0.35 allow low-privileged users to achieve remote code execution on the Probe container by escaping the Playwright sand...

2026-03-27
CVE-2026-33142
Analyzed
8.1
OneUptime Multiple Products

OneUptime is a solution for monitoring and managing online services

2026-03-21
CVE-2026-32308
Analyzed
7.6
OneUptime Multiple Products

OneUptime is a solution for monitoring and managing online services

2026-03-14
CVE-2026-32306
Analyzed
9.9
OneUptime OneUptime

OneUptime versions prior to 10.0.23 are vulnerable to SQL injection in the telemetry aggregation API due to improper interpolation of user-controlled...

2026-03-14
CVE-2026-30957
Analyzed
9.9
OneUptime OneUptime Synthetic Monitors

A server-side RCE vulnerability in OneUptime Synthetic Monitors allows low-privileged users to execute arbitrary commands by abusing exposed Playwrigh...

2026-03-11
CVE-2026-30956
Analyzed
9.9
OneUptime OneUptime

A critical authorization bypass in OneUptime allows low-privileged users to forge headers, escape tenant isolation, and achieve full account takeover...

2026-03-11
CVE-2026-30921
Analyzed
9.9
OneUptime OneUptime Synthetic Monitors

Low-privileged users in OneUptime can achieve server-side RCE by abusing injected Playwright browser objects within Synthetic Monitors to spawn arbitr...

2026-03-11
CVE-2026-30920
Analyzed
8.6
OneUptime App callback

OneUptime is a solution for monitoring and managing online services

2026-03-11
CVE-2026-30887
Analyzed
9.9
OneUptime OneUptime Synthetic Monitors

OneUptime Synthetic Monitors are vulnerable to a sandbox escape via the Node.js vm module, allowing authenticated users to achieve remote code executi...

2026-03-11
CVE-2026-28787
Analyzed
8.2
OneUptime Multiple Products

OneUptime is a solution for monitoring and managing online services

2026-03-06
CVE-2026-27728
Analyzed
9.9
OneUptime OneUptime

An OS command injection vulnerability in OneUptime allows authenticated users to execute arbitrary commands on the Probe server via the monitor destin...

2026-02-26
CVE-2026-27574
Analyzed
9.9
OneUptime OneUptime

A sandbox escape in OneUptime allows users with low privileges or anonymous access to execute arbitrary code and gain full access to cluster credentia...

2026-02-22