1password records
12 published records for vendor 1password.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1289 Improper Validation of Unsafe Equivalence in Input2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-427 Uncontrolled Search Path Element1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-10256No exploit | An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge1password · command line interface | Critical9.8 | — | 0.9% | Oct 27, 2020 |
31Monitor | CVE-2020-18173No exploit | A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.1password · 1password · CWE-427 | High7.8 | — | 0.5% | Jul 26, 2021 |
31Monitor | CVE-2024-42219No exploit | 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is 1password · 1password · CWE-1289 | High7.8 | — | 0.3% | Aug 6, 2024 |
26Monitor | CVE-2021-26905No exploit | 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key1password · scim bridge · CWE-287 | Medium6.5 | — | 1.0% | Feb 8, 2021 |
26Monitor | CVE-2021-41795No exploit | The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass.1password · 1password | Medium6.5 | — | 0.9% | Sep 29, 2021 |
25Monitor | CVE-2018-13042Proof of concept | The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability.1password · 1password · CWE-20 | Medium5.9 | — | 7.9% | Oct 5, 2018 |
22Monitor | CVE-2014-3753No exploit | AgileBits 1Password through 1.0.9.340 allows security feature bypass1password · 1password · CWE-200 | Medium5.5 | — | 0.9% | Jan 9, 2020 |
22Monitor | CVE-2022-29868No exploit | 1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass.1password · 1password · CWE-312 | Medium5.5 | — | 0.2% | May 9, 2022 |
21Monitor | CVE-2021-36758No exploit | 1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be us1password · connect · CWE-20 | Medium5.4 | — | 0.5% | Jul 15, 2021 |
19Monitor | CVE-2022-32550No exploit | An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to t1password · 1password | Medium4.8 | — | 0.5% | Jun 15, 2022 |
18Monitor | CVE-2024-42218No exploit | 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.1password · 1password · CWE-1289 | Medium4.7 | — | 0.2% | Aug 6, 2024 |
17Monitor | CVE-2012-6369No exploit | Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote att1password · 1password · CWE-79 | Medium4.3 | — | 1.0% | Dec 28, 2012 |
- CVE-2020-1025639Monitor
An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge
CriticalCVSS 9.8No exploitEPSS 1%1password · command line interfaceOct 27, 2020
- CVE-2020-1817331Monitor
A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.
HighCVSS 7.8No exploitEPSS 0%1password · 1passwordJul 26, 2021
- CVE-2024-4221931Monitor
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is
HighCVSS 7.8No exploitEPSS 0%1password · 1passwordAug 6, 2024
- CVE-2021-2690526Monitor
1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key
MediumCVSS 6.5No exploitEPSS 1%1password · scim bridgeFeb 8, 2021
- CVE-2021-4179526Monitor
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass.
MediumCVSS 6.5No exploitEPSS 1%1password · 1passwordSep 29, 2021
- CVE-2018-1304225Monitor
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability.
MediumCVSS 5.9Proof of conceptEPSS 8%1password · 1passwordOct 5, 2018
- CVE-2014-375322Monitor
AgileBits 1Password through 1.0.9.340 allows security feature bypass
MediumCVSS 5.5No exploitEPSS 1%1password · 1passwordJan 9, 2020
- CVE-2022-2986822Monitor
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass.
MediumCVSS 5.5No exploitEPSS 0%1password · 1passwordMay 9, 2022
- CVE-2021-3675821Monitor
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be us
MediumCVSS 5.4No exploitEPSS 0%1password · connectJul 15, 2021
- CVE-2022-3255019Monitor
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to t
MediumCVSS 4.8No exploitEPSS 1%1password · 1passwordJun 15, 2022
- CVE-2024-4221818Monitor
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
MediumCVSS 4.7No exploitEPSS 0%1password · 1passwordAug 6, 2024
- CVE-2012-636917Monitor
Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote att
MediumCVSS 4.3No exploitEPSS 1%1password · 1passwordDec 28, 2012