Skip to content
Noroxi

1password records

12 published records for vendor 1password.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

12 records
  • An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge

    CriticalCVSS 9.8No exploitEPSS 1%

    1password · command line interfaceOct 27, 2020

  • A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.

    HighCVSS 7.8No exploitEPSS 0%

    1password · 1passwordJul 26, 2021

  • 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is

    HighCVSS 7.8No exploitEPSS 0%

    1password · 1passwordAug 6, 2024

  • 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key

    MediumCVSS 6.5No exploitEPSS 1%

    1password · scim bridgeFeb 8, 2021

  • The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass.

    MediumCVSS 6.5No exploitEPSS 1%

    1password · 1passwordSep 29, 2021

  • The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability.

    MediumCVSS 5.9Proof of conceptEPSS 8%

    1password · 1passwordOct 5, 2018

  • CVE-2014-3753
    22Monitor

    AgileBits 1Password through 1.0.9.340 allows security feature bypass

    MediumCVSS 5.5No exploitEPSS 1%

    1password · 1passwordJan 9, 2020

  • 1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass.

    MediumCVSS 5.5No exploitEPSS 0%

    1password · 1passwordMay 9, 2022

  • 1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be us

    MediumCVSS 5.4No exploitEPSS 0%

    1password · connectJul 15, 2021

  • An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to t

    MediumCVSS 4.8No exploitEPSS 1%

    1password · 1passwordJun 15, 2022

  • 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

    MediumCVSS 4.7No exploitEPSS 0%

    1password · 1passwordAug 6, 2024

  • CVE-2012-6369
    17Monitor

    Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote att

    MediumCVSS 4.3No exploitEPSS 1%

    1password · 1passwordDec 28, 2012