Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
1day-archive — Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting exploitation techniques in the 1-day window. | Kitploit
Tools/GitHubGitHub/1dayexploit/1day-archive
Vulnerability AnalysisExploitationReverse EngineeringWeb Application ExploitationPenetration TestingBinary AnalysisLearning & EducationCurated Resources
GitHub1dayexploit/1day-archive

1day-archive

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting exploitation techniques in the 1-day window.

2952 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
Website
1dayexploit

1dayexploit - archive

Technical deep-dives and root cause analyses of recently disclosed CVEs.

Website


About

This repository collects technical write-ups of recently disclosed CVEs — the 1-day window between patch release and widespread exploitation.

Each analysis contains:

  • Affected product, vendor, and version range
  • Patch diff and root cause analysis
  • Proof-of-concept demonstrating the vulnerability
  • Detection guidance for defenders
  • References to the original disclosure

Analyses

CVEVendorProductClassSeverityWrite-up
CVE-2026-59851libsshlibssh 0.12.0Authorization BypassHighRead
CVE-2026-12080QEMU Project / Red HatQEMU Guest Agent 5.2.0 - 11.0.3Privilege EscalationHighRead
CVE-2026-72585Grafana LabsGrafana 11.6.9 - 13.1.3Authorization BypassMediumRead
CVE-2026-66915FabrikFabrik 1.0.0-4.6.6Pre-Auth RCECriticalRead
CVE-2026-72568Redis LabsRedis through 8.8.1Out-of-Bounds ReadHighRead
CVE-2026-72899MetabaseMetabase 0.58.0-0.63.4 (0.58.x - 0.63.x vulnerable range)SQL InjectionCriticalRead
CVE-2026-72898MetabaseMetabase 0.58.0-0.63.4SQL InjectionCriticalRead
CVE-2024-7347F5 Networks / nginx projectnginx 1.5.13 - 1.27.0Buffer Over-read / DoSMediumRead

Full analyses live in their own subdirectories. Browse /analyses for the complete list.


The Collective

1dayexploit is a small, closed team of offensive security researchers publishing technical deep-dives into recently disclosed vulnerabilities.

For our own coordinated-disclosed CVEs, see advisories.


Responsible research. Defenders and red teamers alike.

Download Tool
CVE-2025-24813Apache Software FoundationApache Tomcat 9.0.0-9.0.98, 10.1.0-10.1.34, 11.0.0-11.0.2, 8.5.0-8.5.100Path Equivalence + Unsafe DeserializationCriticalRead
CVE-2026-13001Podlove ProjectPodlove Podcast Publisher 4.5.1RCE via Arbitrary File UploadCriticalRead
CVE-2026-34966GiteaGitea 1.26.4 and earlierSSRFHighRead
CVE-2026-71285Uptime Kuma (louislam)Uptime Kuma 2.1.0-2.5.0Stored XSSHighRead
CVE-2026-71327Traefik LabsTraefik 3.0.0-3.6.24 and 3.7.0-3.7.9Authorization BypassHighRead
CVE-2026-14364Automattic Inc. (WordPress plugin ecosystem)TrueBooker - Appointment Booking and Scheduler System <= 1.2.3Auth Bypass / Account TakeoverCriticalRead
CVE-2026-4878kernel.org (libcap maintainers)libcap 2.04 - 2.77TOCTOU Race ConditionMediumRead
CVE-2026-17594SonatypeNexus Repository 3 (CE and Pro) 3.0.0-3.94.xPrivilege EscalationHighRead
CVE-2026-64638WordPressWordPress Core 4.7.0-7.0.2Pre-Auth RCE via XSSHighRead
CVE-2026-71238DjangoCRMDjangoCRM 0.91 - 2.4.0Information DisclosureCriticalRead
CVE-2026-71269OpenJS FoundationNode-RED 3.0.0-5.0.4Denial of ServiceHighRead
CVE-2026-35210OpenCTI Platform / FiligranOpenCTI < 7.260326.0Authorization BypassHighRead
CVE-2026-9082DrupalDrupal core 8.9.0 - 11.3.9 (PostgreSQL)SQL InjectionCriticalRead
CVE-2026-42208BerriAILiteLLM 1.81.16-1.83.6SQL InjectionCriticalRead
CVE-2026-69251FlowiseAIFlowise <= 3.1.2Code Injection / RCECriticalRead
CVE-2025-8110Gogs ProjectGogs 0.13.0-0.13.3Arbitrary File Write via Symlink FollowingHighRead
CVE-2026-66012SiYuan (Open Source)SiYuan kernel 3.7.0 - 3.7.1Auth BypassCriticalRead
CVE-2026-18363osTicket / Enhancesoft LLCosTicket 1.17.x and 1.18.0-1.18.3Auth BypassCriticalRead
CVE-2026-44966shepherdwind / Apache Velocity projectVelocity.js (velocityjs) 0.3.1 - 2.1.5Prototype PollutionHighRead
CVE-2026-45668TriliumNextTrilium Notes 0.0.9 - 0.102.1Path Traversal + RCECriticalRead
CVE-2026-47668DbGateDbGate 7.1.8 and priorRemote Code ExecutionCriticalRead
CVE-2026-24061GNU ProjectGNU Inetutils telnetd 1.9.3-2.7Argument Injection / Auth BypassCriticalRead
CVE-2026-63030WordPressWordPress 6.9.0-6.9.4, 7.0.0-7.0.1Route Confusion / RCECriticalRead
CVE-2026-42151PrometheusPrometheus 2.48.0-3.5.2, 3.6.0-3.11.2Information DisclosureHighRead
CVE-2026-37709GrokabilitySnipe-IT 8.4.0 and beforeAuthorization BypassCriticalRead
CVE-2026-33589-Open Notebook 1.8.3Path Traversal / LFIHighRead
CVE-2026-7482Ollama ProjectOllama < 0.17.1Heap Out-of-Bounds Read / Info DisclosureCriticalRead
CVE-2026-27960OpenCTI-PlatformOpenCTI 6.6.0-6.9.12Authentication BypassCriticalRead