Nawaz Dhandala
6 exploits
Active since Feb 2026
OneUptime: Missing Authentication on Notification Endpoints
CVSS 9.1
OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure
CVSS 8.1
OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verification
CVSS 8.1
OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
CVSS 9.9
OneUptime <10.0.7 - Command Injection
CVSS 9.9
OneUptime <=9.5.13 - Code Injection
CVSS 9.9