Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
1day-archive — Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting exploitation techniques in the 1-day window. | Kitploit
Tools/GitHubGitHub/1dayexploit/1day-archive
Vulnerability AnalysisExploitationReverse EngineeringWeb Application ExploitationPenetration TestingBinary AnalysisLearning & EducationCurated Resources
GitHub1dayexploit/1day-archive

1day-archive

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting exploitation techniques in the 1-day window.

308vor 22h 47mVon Kitploit geprüft
Repository anzeigen
Webseite

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Inhalt in der angeforderten Sprache nicht verfügbar. Englische Version wird angezeigt.
1dayexploit

1dayexploit - archive

Technical deep-dives and root cause analyses of recently disclosed CVEs.

Website


About

This repository collects technical write-ups of recently disclosed CVEs — the 1-day window between patch release and widespread exploitation.

Each analysis contains:

  • Affected product, vendor, and version range
  • Patch diff and root cause analysis
  • Proof-of-concept demonstrating the vulnerability
  • Detection guidance for defenders
  • References to the original disclosure

Analyses

CVEVendorProductClassSeverityWrite-up
CVE-2026-75816DynamiAppsFrontend Admin <= 3.29.12 (WordPress plugin acf-frontend-form-element)Auth BypassCriticalRead
CVE-2026-16723Alibabafastjson 1.2.68-1.2.83Unsafe Class Resolution / RCECriticalRead
CVE-2026-83627WPMU DEVHummingbird <= 3.21.0Code Injection / RCECriticalRead
CVE-2026-59313Spring (VMware Tanzu / Broadcom)Spring Framework 5.3.0-5.3.49, 6.0.0-6.0.30, 6.1.0-6.1.28, 6.2.0-6.2.19, 7.0.0-7.0.8CR/LF InjectionCriticalRead
CVE-2026-76581Incsub / WPMU DEVWPMU DEV Dashboard 5.0.1Auth BypassCriticalRead
CVE-2025-55182Meta / Facebook Inc.React Server Components 19.0.0, 19.1.0-19.1.1, 19.2.0Insecure Deserialization / RCECriticalRead
CVE-2026-55634PimcorePimcore 11.5.x, 12.3.x, 2026.1.xPHP Code Injection + SQL Identifier InjectionCriticalRead
CVE-2026-16639Drupal Security TeamInternationalization Single Sign-On (i18n_sso) - versions < 8.x-1.8

Full analyses live in their own subdirectories. Browse /analyses for the complete list.


The Collective

1dayexploit is a small, closed team of offensive security researchers publishing technical deep-dives into recently disclosed vulnerabilities.

For our own coordinated-disclosed CVEs, see advisories.


Responsible research. Defenders and red teamers alike.

Tool herunterladen
Authentication Bypass
Critical
Read
CVE-2026-68525Apache Software FoundationApache Tomcat 7.0.0 - 11.0.24Authorization BypassCriticalRead
CVE-2026-77998miniOrangeminiOrange SAML SSO for Joomla < 11.0.2, SAML SP Single Sign On - Login with ADFS < 6.4, SAML SP Single Sign On - SAML SSO login with Google Apps < 6.4Authentication BypassCriticalRead
CVE-2026-18963Red Hat / Keycloak ProjectKeycloak 26.0.0 - 26.7.1Auth BypassCriticalRead
CVE-2026-10053GitLab B.V.GitLab CE/EE 18.8 - 19.2.1Path Traversal / Arbitrary File WriteHighRead
CVE-2026-77647SPIPSPIP < 4.4.20Code Injection / RCECriticalRead
CVE-2026-19478GitLab B.V.GitLab CE/EE 18.2-19.2.3Authorization BypassCriticalRead
CVE-2026-55674Discourse ProjectDiscourse 3.5.0.beta2 - 2026.6.0XSS (Cache Poisoning)CriticalRead
CVE-2026-75143FFmpegFFmpeg 4.4 - 9.0Heap Buffer OverflowCriticalRead
CVE-2026-18051BoldGridW3 Total Cache < 2.10.5Path Traversal (Arbitrary File Write)CriticalRead
CVE-2026-18366Automast LtdEvents Manager 7.1 - 7.4.0.1Privilege EscalationCriticalRead
CVE-2026-47686patriksimek (vm2 project)vm2 <= 3.11.5Sandbox Escape / RCECriticalRead
CVE-2026-15571KeycloakKeycloak 26.7.x, 26.6.xAuthentication BypassHighRead
CVE-2026-42945F5 / NGINX IncNGINX Open Source, NGINX Plus 0.6.27-1.30.0Heap Buffer OverflowCriticalRead
CVE-2021-20295QEMU ProjectQEMU 2.6.0-5.0.x; libslirp <= 4.3.0Out-of-Bounds ReadMediumRead
CVE-2026-56654Gitea ProjectGitea 1.26.4 and earlierPrivilege EscalationCriticalRead
CVE-2026-19598The Pods TeamPods - Custom Content Types and Fields 3.3.0-3.3.9Authorization BypassCriticalRead
CVE-2026-28185rtCampLog in with Google 1.4.2Auth BypassCriticalRead
CVE-2026-34486Apache Software FoundationApache Tomcat 9.0.116, 10.1.53, 11.0.20Encryption Bypass / RCEHighRead
CVE-2026-3195QEMU ProjectQEMU 8.2.0-10.2.1Heap Buffer OverflowHighRead
CVE-2025-12464QEMU ProjectQEMU 8.1.0 - 10.1.2 (e1000 network device)Buffer OverflowMediumRead
CVE-2019-10349Jenkins ProjectJenkins Dependency Graph Viewer Plugin 0.13Stored XSSMediumRead
CVE-2026-3842QEMU ProjectQEMU 7.1.0 - 10.2.1Out-of-Bounds WriteHighRead
CVE-2026-18391Automattic (WooCommerce)WooCommerce Subscriptions < 9.1.0PHP Object Injection / RCECriticalRead
CVE-2026-67282fabrikar.comFabrik 1.0.0-4.6.7PHP Code Injection (RCE)CriticalRead
CVE-2026-72772n8nn8n <= 2.31.4, 2.32.0Authentication BypassHighRead
CVE-2026-59083Apache Software FoundationApache Tomcat 8.5.0-11.0.23Auth Bypass (URL-Encoding Mismatch)CriticalRead
CVE-2026-59851libsshlibssh 0.12.0Authorization BypassHighRead
CVE-2026-12080QEMU Project / Red HatQEMU Guest Agent 5.2.0 - 11.0.3Privilege EscalationHighRead
CVE-2026-72585Grafana LabsGrafana 11.6.9 - 13.1.3Authorization BypassMediumRead
CVE-2026-66915FabrikFabrik 1.0.0-4.6.6Pre-Auth RCECriticalRead
CVE-2026-72568Redis LabsRedis through 8.8.1Out-of-Bounds ReadHighRead
CVE-2026-72899MetabaseMetabase 0.58.0-0.63.4 (0.58.x - 0.63.x vulnerable range)SQL InjectionCriticalRead
CVE-2026-72898MetabaseMetabase 0.58.0-0.63.4SQL InjectionCriticalRead
CVE-2024-7347F5 Networks / nginx projectnginx 1.5.13 - 1.27.0Buffer Over-read / DoSMediumRead
CVE-2025-24813Apache Software FoundationApache Tomcat 9.0.0-9.0.98, 10.1.0-10.1.34, 11.0.0-11.0.2, 8.5.0-8.5.100Path Equivalence + Unsafe DeserializationCriticalRead
CVE-2026-13001Podlove ProjectPodlove Podcast Publisher 4.5.1RCE via Arbitrary File UploadCriticalRead
CVE-2026-34966GiteaGitea 1.26.4 and earlierSSRFHighRead
CVE-2026-71285Uptime Kuma (louislam)Uptime Kuma 2.1.0-2.5.0Stored XSSHighRead
CVE-2026-71327Traefik LabsTraefik 3.0.0-3.6.24 and 3.7.0-3.7.9Authorization BypassHighRead
CVE-2026-14364Automattic Inc. (WordPress plugin ecosystem)TrueBooker - Appointment Booking and Scheduler System <= 1.2.3Auth Bypass / Account TakeoverCriticalRead
CVE-2026-4878kernel.org (libcap maintainers)libcap 2.04 - 2.77TOCTOU Race ConditionMediumRead
CVE-2026-17594SonatypeNexus Repository 3 (CE and Pro) 3.0.0-3.94.xPrivilege EscalationHighRead
CVE-2026-64638WordPressWordPress Core 4.7.0-7.0.2Pre-Auth RCE via XSSHighRead
CVE-2026-71238DjangoCRMDjangoCRM 0.91 - 2.4.0Information DisclosureCriticalRead
CVE-2026-71269OpenJS FoundationNode-RED 3.0.0-5.0.4Denial of ServiceHighRead
CVE-2026-35210OpenCTI Platform / FiligranOpenCTI < 7.260326.0Authorization BypassHighRead
CVE-2026-9082DrupalDrupal core 8.9.0 - 11.3.9 (PostgreSQL)SQL InjectionCriticalRead
CVE-2026-42208BerriAILiteLLM 1.81.16-1.83.6SQL InjectionCriticalRead
CVE-2026-69251FlowiseAIFlowise <= 3.1.2Code Injection / RCECriticalRead
CVE-2025-8110Gogs ProjectGogs 0.13.0-0.13.3Arbitrary File Write via Symlink FollowingHighRead
CVE-2026-66012SiYuan (Open Source)SiYuan kernel 3.7.0 - 3.7.1Auth BypassCriticalRead
CVE-2026-18363osTicket / Enhancesoft LLCosTicket 1.17.x and 1.18.0-1.18.3Auth BypassCriticalRead
CVE-2026-44966shepherdwind / Apache Velocity projectVelocity.js (velocityjs) 0.3.1 - 2.1.5Prototype PollutionHighRead
CVE-2026-45668TriliumNextTrilium Notes 0.0.9 - 0.102.1Path Traversal + RCECriticalRead
CVE-2026-47668DbGateDbGate 7.1.8 and priorRemote Code ExecutionCriticalRead
CVE-2026-24061GNU ProjectGNU Inetutils telnetd 1.9.3-2.7Argument Injection / Auth BypassCriticalRead
CVE-2026-63030WordPressWordPress 6.9.0-6.9.4, 7.0.0-7.0.1Route Confusion / RCECriticalRead
CVE-2026-42151PrometheusPrometheus 2.48.0-3.5.2, 3.6.0-3.11.2Information DisclosureHighRead
CVE-2026-37709GrokabilitySnipe-IT 8.4.0 and beforeAuthorization BypassCriticalRead
CVE-2026-33589-Open Notebook 1.8.3Path Traversal / LFIHighRead
CVE-2026-7482Ollama ProjectOllama < 0.17.1Heap Out-of-Bounds Read / Info DisclosureCriticalRead
CVE-2026-27960OpenCTI-PlatformOpenCTI 6.6.0-6.9.12Authentication BypassCriticalRead