One
This hub aggregates every CVE we track for One, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
38
CVEs tracked
4
Critical
10
High
0
In CISA KEV
Severity distribution
MEDIUM16HIGH10CRITICAL4
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
1
1
0
1
0
9
0
0
1
8
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting One.
- CVE-2026-64632A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
- CVE-2026-65641A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
- CVE-2026-64631A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
- CVE-2026-64634A vulnerability allowing local privilege escalation to the Reporter service context.
- CVE-2026-64633A vulnerability allowing remote unauthenticated code execution on the agent host.
- CVE-2026-64630A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
- CVE-2026-58074A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
- CVE-2026-58075A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
- CVE-2026-12703Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS8.0
- CVE-2026-6840Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0.5.5
- CVE-2026-6839Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prio...6.6
- CVE-2026-41667Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is prior to commit 1.30.0.6.6
- CVE-2026-41666Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version is prior to commit 1.30.0.6.6
- CVE-2026-41665Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors. Affected version is prior to comm...6.1
- CVE-2026-41664Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is prior to commit 1.30.0.6.6
Product normalization is registry-driven with AI assist and human review. How it works