1dayexploit

ÂLIM by 1dayexploit

Automated analysis pipeline

ÂLIM is the automated analysis pipeline built by 1dayexploit. Pointed at a disclosed CVE in open-source software, it studies the vulnerability, rebuilds it in an isolated containerised lab, develops a proof-of-concept and validates that exploit against both vulnerable and patched builds. Every analysis it produces is reviewed by a human researcher before publication.

Automated vulnerability analysisContainerised exploit labsPatch validation

Published research - 52 entries

2026-08-20 CVE-2026-47686 CVE-2026-47686: vm2 Sandbox Escape - RCE PoC
2026-08-19 CVE-2021-20295 CVE-2021-20295: QEMU SLiRP IPv6 OOB Read PoC
2026-08-19 CVE-2026-42945 CVE-2026-42945: NGINX Rift - Heap Buffer Overflow PoC
2026-08-19 CVE-2026-15571 CVE-2026-15571: Keycloak Account Linking Auth Bypass PoC
2026-08-17 CVE-2026-19598 CVE-2026-19598: Pods Auth Bypass - Privilege Escalation PoC
2026-08-17 CVE-2026-56654 CVE-2026-56654: Gitea - Access Token Scope Escalation PoC
2026-08-17 CVE-2026-28185 CVE-2026-28185: Login with Google Auth Bypass PoC
2026-08-15 CVE-2019-10349 CVE-2019-10349: Jenkins Dependency Graph - Stored XSS PoC
2026-08-15 CVE-2026-34486 CVE-2026-34486: Tomcat Tribes RCE PoC
2026-08-15 CVE-2026-3195 CVE-2026-3195: QEMU Virtio-Sound Heap OOB Write PoC
2026-08-15 CVE-2025-12464 CVE-2025-12464: QEMU e1000 - Stack OOB Read PoC
2026-08-14 CVE-2026-3842 CVE-2026-3842: QEMU hv-syndbg OOB Write PoC
2026-08-13 CVE-2026-67282 CVE-2026-67282: Fabrik Unauthenticated RCE PoC
2026-08-13 CVE-2026-72772 CVE-2026-72772: n8n Auth Bypass PoC
2026-08-13 CVE-2026-18391 CVE-2026-18391: WooCommerce Subscriptions - RCE PoC
2026-08-12 CVE-2026-59083 CVE-2026-59083: Apache Tomcat - Auth Bypass PoC
2026-08-11 CVE-2026-12080 CVE-2026-12080: QEMU Guest Agent Symlink Privesc PoC
2026-08-11 CVE-2026-59851 CVE-2026-59851: libssh Authorization Bypass PoC
2026-08-11 CVE-2026-66915 CVE-2026-66915: Fabrik Calc Element RCE PoC
2026-08-11 CVE-2026-72899 CVE-2026-72899: Metabase Unauthenticated SQL Injection PoC
2026-08-11 CVE-2026-72585 CVE-2026-72585: Grafana - Protected Receiver Auth Bypass PoC
2026-08-11 CVE-2026-72898 CVE-2026-72898: Metabase SQL Injection - Admin Takeover PoC
2026-08-11 CVE-2024-7347 CVE-2024-7347: nginx - Buffer Over-read PoC
2026-08-11 CVE-2025-24813 CVE-2025-24813: Apache Tomcat Partial PUT RCE PoC
2026-08-11 CVE-2026-72568 CVE-2026-72568: Redis Heap OOB Read PoC
2026-08-10 CVE-2026-13001 CVE-2026-13001: Podlove Podcast Publisher RCE PoC
2026-08-10 CVE-2026-34966 CVE-2026-34966: Gitea - Authenticated SSRF PoC
2026-08-10 CVE-2026-71285 CVE-2026-71285: Uptime Kuma Matomo Stored XSS PoC
2026-08-09 CVE-2026-71327 CVE-2026-71327: Traefik - Route Identity Collision PoC
2026-08-08 CVE-2026-4878 CVE-2026-4878: libcap TOCTOU Race Privilege Escalation PoC
2026-08-08 CVE-2026-14364 CVE-2026-14364: TrueBooker Auth Bypass PoC
2026-08-08 CVE-2026-17594 CVE-2026-17594: Nexus Privilege Escalation PoC
2026-08-07 CVE-2026-64638 CVE-2026-64638: WordPress XSS2Shell Pre-Auth RCE PoC
2026-08-07 CVE-2026-71238 CVE-2026-71238: DjangoCRM - Debug Disclosure PoC
2026-08-06 CVE-2026-71269 CVE-2026-71269: Node-RED Unauthenticated DoS PoC
2026-08-05 CVE-2026-35210 CVE-2026-35210: OpenCTI Authorization Bypass PoC
2026-08-04 CVE-2026-42208 CVE-2026-42208: LiteLLM Pre-Auth SQL Injection PoC
2026-08-04 CVE-2026-9082 CVE-2026-9082: Drupal SQL Injection PoC
2026-08-04 CVE-2026-69251 CVE-2026-69251: Flowise Authenticated RCE PoC
2026-08-01 CVE-2025-8110 CVE-2025-8110: Gogs Symlink-Following RCE PoC
2026-08-01 CVE-2026-66012 CVE-2026-66012: SiYuan - Auth Bypass to Admin Takeover PoC
2026-07-31 CVE-2026-18363 CVE-2026-18363: osTicket Auth Bypass PoC
2026-07-30 CVE-2026-44966 CVE-2026-44966: Velocity.js Prototype Pollution PoC
2026-07-28 CVE-2026-45668 CVE-2026-45668: Trilium Notes - RCE via Path Traversal PoC
2026-07-24 CVE-2026-63030 CVE-2026-63030: WordPress wp2shell Pre-Auth RCE PoC
2026-07-22 CVE-2026-47668 CVE-2026-47668: DbGate Unauthenticated RCE PoC
2026-05-08 CVE-2026-37709 CVE-2026-37709: Snipe-IT - Auth Bypass PoC
2026-05-07 CVE-2026-33589 CVE-2026-33589: Open Notebook - Path Traversal LFI PoC
2026-05-06 CVE-2026-27960 CVE-2026-27960: OpenCTI Authentication Bypass via Hardcoded UUID PoC
2026-05-05 CVE-2026-42151 CVE-2026-42151: Prometheus - OAuth Secret Exposure PoC
2026-05-04 CVE-2026-7482 CVE-2026-7482 - Ollama Heap Out-of-Bounds Read PoC
2026-01-26 CVE-2026-24061 CVE-2026-24061: GNU Inetutils - Auth Bypass PoC