
Approfondimenti tecnici e analisi delle cause profonde delle CVE divulgate di recente: reverse engineering delle patch, creazione di proof-of-concept e documentazione delle tecniche di sfruttamento nella finestra di 1 giorno.
Analisi tecniche approfondite e root cause analysis di CVE divulgati di recente.
Questo repository raccoglie write-up tecnici di CVE divulgati di recente — la finestra di 1 giorno tra il rilascio della patch e lo sfruttamento su larga scala.
Ogni analisi contiene:
| CVE | Fornitore | Prodotto | Classe | Gravità | Write-up |
|---|
CVE-2026-75816 | DynamiApps | Frontend Admin <= 3.29.12 (plugin WordPress acf-frontend-form-element) | Auth Bypass | Critical | Read |
CVE-2026-16723 | Alibaba | fastjson 1.2.68-1.2.83 | Unsafe Class Resolution / RCE | Critical | Read |
CVE-2026-83627 | WPMU DEV | Hummingbird <= 3.21.0 | Code Injection / RCE | Critical | Read |
CVE-2026-59313 | Spring (VMware Tanzu / Broadcom) | Spring Framework 5.3.0-5.3.49, 6.0.0-6.0.30, 6.1.0-6.1.28, 6.2.0-6.2.19, 7.0.0-7.0.8 | CR/LF Injection | Critical | Read |
CVE-2026-76581 | Incsub / WPMU DEV | WPMU DEV Dashboard 5.0.1 | Auth Bypass | Critical | Read |
CVE-2025-55182 | Meta / Facebook Inc. | React Server Components 19.0.0, 19.1.0-19.1.1, 19.2.0 | Insecure Deserialization / RCE | Critical | Read |
CVE-2026-55634 | Pimcore | Pimcore 11.5.x, 12.3.x, 2026.1.x | PHP Code Injection + SQL Identifier Injection | Critical | Read |
CVE-2026-16639 | Drupal Security Team | Internationalization Single Sign-On (i18n_sso) - versioni < 8.x-1.8 | Authentication Bypass | Critical | Read |
CVE-2026-68525 | Apache Software Foundation | Apache Tomcat 7.0.0 - 11.0.24 | Authorization Bypass | Critical | Read |
CVE-2026-77998 | miniOrange | miniOrange SAML SSO for Joomla < 11.0.2, SAML SP Single Sign On - Login with ADFS < 6.4, SAML SP Single Sign On - SAML SSO login with Google Apps < 6.4 | Authentication Bypass | Critical | Read |
CVE-2026-18963 | Red Hat / Keycloak Project | Keycloak 26.0.0 - 26.7.1 | Auth Bypass | Critical | Read |
CVE-2026-10053 | GitLab B.V. | GitLab CE/EE 18.8 - 19.2.1 | Path Traversal / Arbitrary File Write | High | Read |
CVE-2026-77647 | SPIP | SPIP < 4.4.20 | Code Injection / RCE | Critical | Read |
CVE-2026-19478 | GitLab B.V. | GitLab CE/EE 18.2-19.2.3 | Authorization Bypass | Critical | Read |
CVE-2026-55674 | Discourse Project | Discourse 3.5.0.beta2 - 2026.6.0 | XSS (Cache Poisoning) | Critical | Read |
CVE-2026-75143 | FFmpeg | FFmpeg 4.4 - 9.0 | Heap Buffer Overflow | Critical | Read |
CVE-2026-18051 | BoldGrid | W3 Total Cache < 2.10.5 | Path Traversal (Arbitrary File Write) | Critical | Read |
CVE-2026-18366 | Automast Ltd | Events Manager 7.1 - 7.4.0.1 | Privilege Escalation | Critical | Read |
CVE-2026-47686 | patriksimek (vm2 project) | vm2 <= 3.11.5 | Sandbox Escape / RCE | Critical | Read |
CVE-2026-15571 | Keycloak | Keycloak 26.7.x, 26.6.x | Authentication Bypass | High | Read |
CVE-2026-42945 | F5 / NGINX Inc | NGINX Open Source, NGINX Plus 0.6.27-1.30.0 | Heap Buffer Overflow | Critical | Read |
CVE-2021-20295 | QEMU Project | QEMU 2.6.0-5.0.x; libslirp <= 4.3.0 | Out-of-Bounds Read | Medium | Read |
CVE-2026-56654 | Gitea Project | Gitea 1.26.4 e precedenti | Privilege Escalation | Critical | Read |
CVE-2026-19598 | The Pods Team | Pods - Custom Content Types and Fields 3.3.0-3.3.9 | Authorization Bypass | Critical | Read |
CVE-2026-28185 | rtCamp | Log in with Google 1.4.2 | Auth Bypass | Critical | Read |
CVE-2026-34486 | Apache Software Foundation | Apache Tomcat 9.0.116, 10.1.53, 11.0.20 | Encryption Bypass / RCE | High | Read |
CVE-2026-3195 | QEMU Project | QEMU 8.2.0-10.2.1 | Heap Buffer Overflow | High | Read |
CVE-2025-12464 | QEMU Project | QEMU 8.1.0 - 10.1.2 (dispositivo di rete e1000) | Buffer Overflow | Medium | Read |
CVE-2019-10349 | Jenkins Project | Jenkins Dependency Graph Viewer Plugin 0.13 | Stored XSS | Medium | Read |
CVE-2026-3842 | QEMU Project | QEMU 7.1.0 - 10.2.1 | Out-of-Bounds Write | High | Read |
CVE-2026-18391 | Automattic (WooCommerce) | WooCommerce Subscriptions < 9.1.0 | PHP Object Injection / RCE | Critical | Read |
CVE-2026-67282 | fabrikar.com | Fabrik 1.0.0-4.6.7 | PHP Code Injection (RCE) | Critical | Read |
CVE-2026-72772 | n8n | n8n <= 2.31.4, 2.32.0 | Authentication Bypass | High | Read |
CVE-2026-59083 | Apache Software Foundation | Apache Tomcat 8.5.0-11.0.23 | Auth Bypass (URL-Encoding Mismatch) | Critical | Read |
CVE-2026-59851 | libssh | libssh 0.12.0 | Authorization Bypass | High | Read |
CVE-2026-12080 | QEMU Project / Red Hat | QEMU Guest Agent 5.2.0 - 11.0.3 | Privilege Escalation | High | Read |
CVE-2026-72585 | Grafana Labs | Grafana 11.6.9 - 13.1.3 | Authorization Bypass | Medium | Read |
CVE-2026-66915 | Fabrik | Fabrik 1.0.0-4.6.6 | Pre-Auth RCE | Critical | Read |
CVE-2026-72568 | Redis Labs | Redis fino alla 8.8.1 | Out-of-Bounds Read | High | Read |
CVE-2026-72899 | Metabase | Metabase 0.58.0-0.63.4 (intervallo vulnerabile 0.58.x - 0.63.x) | SQL Injection | Critical | Read |
CVE-2026-72898 | Metabase | Metabase 0.58.0-0.63.4 | SQL Injection | Critical | Read |
CVE-2024-7347 | F5 Networks / nginx project | nginx 1.5.13 - 1.27.0 | Buffer Over-read / DoS | Medium | Read |
CVE-2025-24813 | Apache Software Foundation | Apache Tomcat 9.0.0-9.0.98, 10.1.0-10.1.34, 11.0.0-11.0.2, 8.5.0-8.5.100 | Path Equivalence + Unsafe Deserialization | Critical | Read |
CVE-2026-13001 | Podlove Project | Podlove Podcast Publisher 4.5.1 | RCE via Arbitrary File Upload | Critical | Read |
CVE-2026-34966 | Gitea | Gitea 1.26.4 e precedenti | SSRF | High | Read |
CVE-2026-71285 | Uptime Kuma (louislam) | Uptime Kuma 2.1.0-2.5.0 | Stored XSS | High | Read |
CVE-2026-71327 | Traefik Labs | Traefik 3.0.0-3.6.24 e 3.7.0-3.7.9 | Authorization Bypass | High | Read |
CVE-2026-14364 | Automattic Inc. (ecosistema di plugin WordPress) | TrueBooker - Appointment Booking and Scheduler System <= 1.2.3 | Auth Bypass / Account Takeover | Critical | Read |
CVE-2026-4878 | kernel.org (manutentori di libcap) | libcap 2.04 - 2.77 | TOCTOU Race Condition | Medium | Read |
CVE-2026-17594 | Sonatype | Nexus Repository 3 (CE e Pro) 3.0.0-3.94.x | Privilege Escalation | High | Read |
CVE-2026-64638 | WordPress | WordPress Core 4.7.0-7.0.2 | Pre-Auth RCE via XSS | High | Read |
CVE-2026-71238 | DjangoCRM | DjangoCRM 0.91 - 2.4.0 | Information Disclosure | Critical | Read |
CVE-2026-71269 | OpenJS Foundation | Node-RED 3.0.0-5.0.4 | Denial of Service | High | Read |
CVE-2026-35210 | OpenCTI Platform / Filigran | OpenCTI < 7.260326.0 | Authorization Bypass | High | Read |
CVE-2026-9082 | Drupal | Drupal core 8.9.0 - 11.3.9 (PostgreSQL) | SQL Injection | Critical | Read |
CVE-2026-42208 | BerriAI | LiteLLM 1.81.16-1.83.6 | SQL Injection | Critical | Read |
CVE-2026-69251 | FlowiseAI | Flowise <= 3.1.2 | Code Injection / RCE | Critical | Read |
CVE-2025-8110 | Gogs Project | Gogs 0.13.0-0.13.3 | Arbitrary File Write via Symlink Following | High | Read |
CVE-2026-66012 | SiYuan (Open Source) | SiYuan kernel 3.7.0 - 3.7.1 | Auth Bypass | Critical | Read |
CVE-2026-18363 | osTicket / Enhancesoft LLC | osTicket 1.17.x e 1.18.0-1.18.3 | Auth Bypass | Critical | Read |
CVE-2026-44966 | shepherdwind / Apache Velocity project | Velocity.js (velocityjs) 0.3.1 - 2.1.5 | Prototype Pollution | High | Read |
CVE-2026-45668 | TriliumNext | Trilium Notes 0.0.9 - 0.102.1 | Path Traversal + RCE | Critical | Read |
CVE-2026-47668 | DbGate | DbGate 7.1.8 e precedenti | Remote Code Execution | Critical | Read |
CVE-2026-24061 | GNU Project | GNU Inetutils telnetd 1.9.3-2.7 | Argument Injection / Auth Bypass | Critical | Read |
CVE-2026-63030 | WordPress | WordPress 6.9.0-6.9.4, 7.0.0-7.0.1 | Route Confusion / RCE | Critical | Read |
CVE-2026-42151 | Prometheus | Prometheus 2.48.0-3.5.2, 3.6.0-3.11.2 | Information Disclosure | High | Read |
CVE-2026-37709 | Grokability | Snipe-IT 8.4.0 e precedenti | Authorization Bypass | Critical | Read |
CVE-2026-33589 | - | Open Notebook 1.8.3 | Path Traversal / LFI | High | Read |
CVE-2026-7482 | Ollama Project | Ollama < 0.17.1 | Heap Out-of-Bounds Read / Info Disclosure | Critical | Read |
CVE-2026-27960 | OpenCTI-Platform | OpenCTI 6.6.0-6.9.12 | Authentication Bypass | Critical | Read |
Le analisi complete si trovano nelle rispettive sottodirectory. Sfoglia
/analysesper l'elenco completo.
1dayexploit è un piccolo team chiuso di ricercatori di sicurezza offensiva che pubblica analisi tecniche approfondite su vulnerabilità divulgate di recente.
Per i nostri CVE divulgati in modo coordinato, vedi advisories.
Ricerca responsabile. Difensori e red teamer allo stesso modo.