Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
1day-archive — Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting exploitation techniques in the 1-day window. | Kitploit
Tools/GitHubGitHub/1dayexploit/1day-archive
Vulnerability AnalysisExploitationReverse EngineeringWeb Application ExploitationPenetration TestingBinary AnalysisLearning & EducationCurated Resources
GitHub1dayexploit/1day-archive

1day-archive

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting exploitation techniques in the 1-day window.

301195 days agoReviewed by Kitploit
View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
1dayexploit

1dayexploit - archive

Technical deep-dives and root cause analyses of recently disclosed CVEs.

Website


About

This repository collects technical write-ups of recently disclosed CVEs — the 1-day window between patch release and widespread exploitation.

Each analysis contains:

  • Affected product, vendor, and version range
  • Patch diff and root cause analysis
  • Proof-of-concept demonstrating the vulnerability
  • Detection guidance for defenders
  • References to the original disclosure

Analyses

CVEVendorProductClassSeverityWrite-up
CVE-2026-75816DynamiAppsFrontend Admin <= 3.29.12 (WordPress plugin acf-frontend-form-element)Auth BypassCriticalRead
CVE-2026-16723Alibabafastjson 1.2.68-1.2.83Unsafe Class Resolution / RCECriticalRead
CVE-2026-83627WPMU DEVHummingbird <= 3.21.0Code Injection / RCECriticalRead
CVE-2026-59313Spring (VMware Tanzu / Broadcom)Spring Framework 5.3.0-5.3.49, 6.0.0-6.0.30, 6.1.0-6.1.28, 6.2.0-6.2.19, 7.0.0-7.0.8CR/LF InjectionCriticalRead
CVE-2026-76581Incsub / WPMU DEVWPMU DEV Dashboard 5.0.1Auth BypassCriticalRead
CVE-2025-55182Meta / Facebook Inc.React Server Components 19.0.0, 19.1.0-19.1.1, 19.2.0Insecure Deserialization / RCECriticalRead
CVE-2026-55634PimcorePimcore 11.5.x, 12.3.x, 2026.1.xPHP Code Injection + SQL Identifier InjectionCriticalRead
CVE-2026-16639Drupal Security TeamInternationalization Single Sign-On (i18n_sso) - versions < 8.x-1.8Authentication BypassCriticalRead
CVE-2026-68525Apache Software FoundationApache Tomcat 7.0.0 - 11.0.24Authorization BypassCriticalRead
CVE-2026-77998miniOrangeminiOrange SAML SSO for Joomla < 11.0.2, SAML SP Single Sign On - Login with ADFS < 6.4, SAML SP Single Sign On - SAML SSO login with Google Apps < 6.4Authentication BypassCriticalRead
CVE-2026-18963Red Hat / Keycloak ProjectKeycloak 26.0.0 - 26.7.1Auth BypassCriticalRead
CVE-2026-10053GitLab B.V.GitLab CE/EE 18.8 - 19.2.1Path Traversal / Arbitrary File WriteHighRead
CVE-2026-77647SPIPSPIP < 4.4.20Code Injection / RCECriticalRead
CVE-2026-19478GitLab B.V.GitLab CE/EE 18.2-19.2.3Authorization BypassCriticalRead
CVE-2026-55674Discourse ProjectDiscourse 3.5.0.beta2 - 2026.6.0XSS (Cache Poisoning)CriticalRead
CVE-2026-75143FFmpegFFmpeg 4.4 - 9.0Heap Buffer OverflowCriticalRead
CVE-2026-18051BoldGridW3 Total Cache < 2.10.5Path Traversal (Arbitrary File Write)CriticalRead
CVE-2026-18366Automast LtdEvents Manager 7.1 - 7.4.0.1Privilege EscalationCriticalRead
CVE-2026-47686patriksimek (vm2 project)vm2 <= 3.11.5Sandbox Escape / RCECriticalRead
CVE-2026-15571KeycloakKeycloak 26.7.x, 26.6.xAuthentication BypassHighRead
CVE-2026-42945F5 / NGINX IncNGINX Open Source, NGINX Plus 0.6.27-1.30.0Heap Buffer OverflowCriticalRead
CVE-2021-20295QEMU ProjectQEMU 2.6.0-5.0.x; libslirp <= 4.3.0Out-of-Bounds ReadMediumRead
CVE-2026-56654Gitea ProjectGitea 1.26.4 and earlierPrivilege EscalationCriticalRead
CVE-2026-19598The Pods TeamPods - Custom Content Types and Fields 3.3.0-3.3.9Authorization BypassCriticalRead
CVE-2026-28185rtCampLog in with Google 1.4.2Auth BypassCriticalRead
CVE-2026-34486Apache Software FoundationApache Tomcat 9.0.116, 10.1.53, 11.0.20Encryption Bypass / RCEHighRead
CVE-2026-3195QEMU ProjectQEMU 8.2.0-10.2.1Heap Buffer OverflowHighRead
CVE-2025-12464QEMU ProjectQEMU 8.1.0 - 10.1.2 (e1000 network device)Buffer OverflowMediumRead
CVE-2019-10349Jenkins ProjectJenkins Dependency Graph Viewer Plugin 0.13Stored XSSMediumRead
CVE-2026-3842QEMU ProjectQEMU 7.1.0 - 10.2.1Out-of-Bounds WriteHighRead
CVE-2026-18391Automattic (WooCommerce)WooCommerce Subscriptions < 9.1.0PHP Object Injection / RCECriticalRead
Download Tool