
1day-archive
Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

autonomous red teaming platform; multi-agent offensive-security meta-harness

CVE-2026-3805: Use-After-Free in curl SMB connection reuse - heap info disclosure

WebKit NavigateEvent.canIntercept SOP bypass via cross-port interception — iOS 26.3.1 BSI (CVE-2026-20643)

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)

Automated exploit for CVE-2025-66034, chaining path traversal and XML injection in fontTools varLib to achieve unauthenticated remote code execution…

An implementation of a proof-of-concept for CVE-2020-12124

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

D-link AX1500 Vulnerability

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera


activemq-rce-cve-2023-46604


CVE-2023-33381: OS command injection on MitraStar GPT-2741GNAC