1dayexploit
Cyber security research hub

We research the 1-day

The 1-day is the interval between a patch landing and widespread exploitation - defenders racing to deploy, attackers racing to reverse-engineer. We sit in the middle: analyzing, documenting, publishing.

Not a patch-diff feed. We turn CVE claims into evidence and go past the single bug to the techniques behind it - and we are building a community of practitioners to share methods and argue findings in public.

Root cause Traced through the source, not paraphrased from an advisory - why the flaw exists, at the code level.
Techniques & methods Exploitation primitives, bypass patterns and tooling - the transferable part that outlives any one CVE.
Working PoCs Runnable proof-of-concept code, validated against both the vulnerable and the patched build.
Community Open to anyone doing the work. Send a write-up, a CVE worth analysing, or a correction - credited either way.
Our engine

ÂLIM analyses CVEs on its own.

ÂLIM is our AI-driven analysis engine. Point it at a disclosed CVE in open-source software and it works the flaw end to end without an analyst driving each step: it studies the vulnerability, rebuilds it in an isolated containerised lab, develops a working proof-of-concept, and validates that exploit against both the vulnerable and the patched build.

That last part is the point. A result is only reported once the exploit has been shown to fire on the unpatched build and to stop working on the fixed one - so what we publish is demonstrated, not asserted.

Open source only Targets have to be buildable from source. Kernels, firmware, hardware and closed-source products cannot be labbed, so they are out of scope.
Vulnerable vs patched Every analysis runs against both builds, which is what separates a proven finding from a plausible one.
Request an analysis The catalogue is public and anyone can ask for a specific CVE to be looked at. Email only, no account.
Recent research view all →
2026-07-28 CVE-2026-45668 CVE-2026-45668: Trilium Notes - RCE via Path Traversal PoC
2026-07-24 CVE-2026-63030 CVE-2026-63030: WordPress wp2shell Pre-Auth RCE PoC
2026-07-22 CVE-2026-47668 CVE-2026-47668: DbGate Unauthenticated RCE PoC
Get in touch

Found something? Want to publish with us?

Send us a write-up, a CVE worth analysing, or a correction to something we published - corrections are welcome and credited. For sensitive reports, use our PGP key. If you would like to support the project, the same address reaches us.