Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. 1Password/
  3. 1Password Password Manager

1Password Password Manager

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 13 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Password manager for storing, generating, and autofilling credentials

by 1Password · 1password.com · source ↗

Screenshots

1
1Password Password Manager — screenshotauto

Known CVEs (13)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2024-42219 ↗HIGH 7.82024

    1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.

  • CVE-2024-42218 ↗MEDIUM 4.72024

    1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

  • CVE-2022-32550 ↗MEDIUM 4.82022

    An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue …

  • CVE-2022-29868 ↗MEDIUM 5.52022

    1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Pa…

  • CVE-2021-41795 ↗MEDIUM 6.52021

    The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web p…

  • CVE-2020-18173 ↗HIGH 7.82021

    A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.

  • CVE-2021-36758 ↗MEDIUM 5.42021

    1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authoriz…

  • CVE-2021-26905 ↗MEDIUM 6.52021

    1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key.

  • CVE-2020-10256 ↗CRITICAL 9.82020

    An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was use…

  • CVE-2014-3753 ↗MEDIUM 5.52020

    AgileBits 1Password through 1.0.9.340 allows security feature bypass

  • CVE-2018-19863 ↗MEDIUM 5.52018

    An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data passed from Safari to 1Password could be logged loca…

  • CVE-2018-13042 ↗MEDIUM 5.92018

    The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.…

  • CVE-2012-6369 ↗MEDIUM 4.32012

    Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted …

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Password Management products

see all →
  • 1Password Enterprise Password Manager · 1Password
  • 1Password Enterprise Password Manager - MSP Edition · 1Password
  • 1Password Teams Starter Pack · 1Password
  • Akeyless Password Manager · Akeyless Security
  • Avatier Password Bouncer · Avatier
  • Avira Password Manager · Avira
  • Bitwarden Enterprise · Bitwarden
  • CatchProbe ActiveGuard · CatchProbe