CVE Tools

One

38 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for One, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

One CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
One CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-121
2026-010
2026-021
2026-030
2026-049
2026-050
2026-060
2026-071
2026-088
2026-090

Severity

How the 38 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical413%
  • High1033%
  • Medium1653%

Latest CVEs

The 15 most recently published vulnerabilities affecting One.

  1. CVE-2026-64632A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.—
  2. CVE-2026-65641A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.—
  3. CVE-2026-64631A vulnerability allowing a low-privileged user to inject SQL and extract database contents.—
  4. CVE-2026-64634A vulnerability allowing local privilege escalation to the Reporter service context.—
  5. CVE-2026-64633A vulnerability allowing remote unauthenticated code execution on the agent host.—
  6. CVE-2026-64630A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.—
  7. CVE-2026-58074A vulnerability allowing a high-privileged user to execute arbitrary code on the server.—
  8. CVE-2026-58075A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.—
  9. CVE-2026-12703Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS8.0
  10. CVE-2026-6840Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0.5.5
  11. CVE-2026-6839Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prio...6.6
  12. CVE-2026-41667Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is prior to commit 1.30.0.6.6
  13. CVE-2026-41666Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version is prior to commit 1.30.0.6.6
  14. CVE-2026-41665Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors. Affected version is prior to comm...6.1
  15. CVE-2026-41664Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is prior to commit 1.30.0.6.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store