Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

1password

First CVE: Dec 28, 2012Active for: 14 yearsTotal CVEs: 12
19.3
VTI Score
Low

1Password maintains a focused portfolio of password management and secrets-handling applications, including its core vault product, command-line interface, and browser integration, deployed across consumer and enterprise environments where credential security is paramount. Vulnerabilities affecting the vendor concentrate on input-handling and information-disclosure weakness classes—improper input validation, unsafe equivalence checks, and cleartext storage of sensitive data—that reflect the parsing and cryptographic-boundary demands of credential-management software and frequently acquire public exploit code. Defenders should prioritize this vendor's updates given the sensitivity of data the products protect; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 1password over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2012
13 years ago
Most Recent CVE
Aug 6, 2024
716 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-13042MEDIUM
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivi
Oct 5, 20185.935NOYES
CVE-2024-42219HIGH
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.
Aug 6, 20247.825NONO
CVE-2020-18173HIGH
A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.
Jul 26, 20217.825NONO
CVE-2020-10256CRITICAL
An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random numb
Oct 27, 20209.824NONO
CVE-2021-41795MEDIUM
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extensio
Sep 29, 20216.522NONO
CVE-2021-26905MEDIUM
1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key.
Feb 8, 20216.521NONO
CVE-2022-29868MEDIUM
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Passwo
May 9, 20225.520NONO
CVE-2021-36758MEDIUM
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Mali
Jul 16, 20215.420NONO
CVE-2024-42218MEDIUM
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
Aug 6, 20244.719NONO
CVE-2022-32550MEDIUM
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circum
Jun 15, 20224.818NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
75%
17%
8%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (41.7%)
Network6 (50.0%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (66.7%)
High3 (25.0%)
Unknown1 (8.3%)
User Interaction
None8 (66.7%)
Unknown1 (8.3%)
Required3 (25.0%)
Privileges Required
Low5 (41.7%)
High0 (0.0%)
None6 (50.0%)
Unknown1 (8.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 1password.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 1password — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 1password's Products

View all 1 CNAs →

Top CWEs