<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>1dayexploit</title>
    <link>https://1dayexploit.com</link>
    <atom:link href="https://1dayexploit.com/rss.xml" rel="self" type="application/rss+xml"/>
    <description>Technical deep-dives into recently disclosed CVEs.</description>
    <language>en</language>
    <lastBuildDate>Fri, 28 Aug 2026 23:58:46 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-16639: Drupal i18n_sso Auth Bypass</title>
      <link>https://1dayexploit.com/blog/cve-2026-16639-drupal-i18n-sso-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-16639-drupal-i18n-sso-auth-bypass/</guid>
      <pubDate>Sat, 29 Aug 2026 14:30:00 GMT</pubDate>
      <description>CVE-2026-16639: Drupal Internationalization Single Sign-On authentication bypass via SQL LIKE wildcard injection and predictable token generation (CVSS 9.8)</description>
      <category>CVE-2026-16639</category>
    </item>
    <item>
      <title>CVE-2026-68525: Apache Tomcat - Auth Bypass</title>
      <link>https://1dayexploit.com/blog/cve-2026-68525-apache-tomcat-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-68525-apache-tomcat-auth-bypass/</guid>
      <pubDate>Sat, 29 Aug 2026 14:30:00 GMT</pubDate>
      <description>Authorization bypass in Apache Tomcat FORM authentication allows low-privilege users to execute POST requests restricted to admin roles by exploiting a method-rewrite bug in saved request restoration.</description>
      <category>CVE-2026-68525</category>
    </item>
    <item>
      <title>CVE-2026-77998: miniOrange SAML - Joomla Auth Bypass</title>
      <link>https://1dayexploit.com/blog/cve-2026-77998-miniorange-saml-joomla-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-77998-miniorange-saml-joomla-auth-bypass/</guid>
      <pubDate>Thu, 27 Aug 2026 10:00:00 GMT</pubDate>
      <description>CVE-2026-77998: miniOrange SAML SSO for Joomla authentication bypass via improper tri-state signature verification. Unauthenticated attackers can log in as any existing user.</description>
      <category>CVE-2026-77998</category>
    </item>
    <item>
      <title>CVE-2026-10053: GitLab npm Path Traversal RCE</title>
      <link>https://1dayexploit.com/blog/cve-2026-10053-gitlab-npm-path-traversal-rce/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-10053-gitlab-npm-path-traversal-rce/</guid>
      <pubDate>Tue, 25 Aug 2026 14:30:00 GMT</pubDate>
      <description>CVE-2026-10053 (CVSS 8.5): GitLab npm registry path traversal allows authenticated arbitrary file write and RCE via package poisoning on consumers.</description>
      <category>CVE-2026-10053</category>
    </item>
    <item>
      <title>CVE-2026-18963: Keycloak - Auth Bypass</title>
      <link>https://1dayexploit.com/blog/cve-2026-18963-keycloak-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-18963-keycloak-auth-bypass/</guid>
      <pubDate>Tue, 25 Aug 2026 08:30:00 GMT</pubDate>
      <description>CVE-2026-18963: Keycloak unauthenticated account takeover via reset-credentials flow - attacker sets arbitrary password without email verification, CVSS 9.1 critical.</description>
      <category>CVE-2026-18963</category>
    </item>
    <item>
      <title>CVE-2026-77647: SPIP Pre-Auth RCE</title>
      <link>https://1dayexploit.com/blog/cve-2026-77647-spip-pre-auth-rce/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-77647-spip-pre-auth-rce/</guid>
      <pubDate>Mon, 24 Aug 2026 10:15:00 GMT</pubDate>
      <description>CVE-2026-77647 is a pre-authentication remote code execution in SPIP before 4.4.20. A regex-based template compiler flaw combined with raw var_export() allows unauthenticated attackers to inject arbitrary PHP code.</description>
      <category>CVE-2026-77647</category>
    </item>
    <item>
      <title>CVE-2026-55674: Discourse Cache Poisoning XSS</title>
      <link>https://1dayexploit.com/blog/cve-2026-55674-discourse-cache-poisoning-xss/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-55674-discourse-cache-poisoning-xss/</guid>
      <pubDate>Fri, 21 Aug 2026 14:30:00 GMT</pubDate>
      <description>Discourse 3.5.0-beta2 through 2026.1.5 allows unauthenticated XSS via color scheme cookies that bypass CSP and poison the anonymous cache to all visitors. CVSS 9.3 critical.</description>
      <category>CVE-2026-55674</category>
    </item>
    <item>
      <title>CVE-2026-19478: GitLab GraphQL Auth Bypass</title>
      <link>https://1dayexploit.com/blog/cve-2026-19478-gitlab-graphql-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-19478-gitlab-graphql-auth-bypass/</guid>
      <pubDate>Fri, 21 Aug 2026 02:15:00 GMT</pubDate>
      <description>CVE-2026-19478: Unauthenticated GitLab authorization bypass via GraphQL @gl_introduced directive, allowing arbitrary method invocation on public projects. CRITICAL.</description>
      <category>CVE-2026-19478</category>
    </item>
    <item>
      <title>CVE-2026-75143: FFmpeg RIST Heap OOB Write</title>
      <link>https://1dayexploit.com/blog/cve-2026-75143-ffmpeg-rist-heap-oob-write/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-75143-ffmpeg-rist-heap-oob-write/</guid>
      <pubDate>Thu, 20 Aug 2026 13:35:00 GMT</pubDate>
      <description>FFmpeg CVE-2026-75143: RIST protocol reader heap buffer overflow, remote unauthenticated DoS via oversized payload in async:rist:// receiver</description>
      <category>CVE-2026-75143</category>
    </item>
    <item>
      <title>CVE-2026-18051: W3 Total Cache - Arbitrary File Write</title>
      <link>https://1dayexploit.com/blog/cve-2026-18051-w3-total-cache-arbitrary-file-write/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-18051-w3-total-cache-arbitrary-file-write/</guid>
      <pubDate>Thu, 20 Aug 2026 13:00:00 GMT</pubDate>
      <description>CVE-2026-18051 is a critical unauthenticated path traversal vulnerability in W3 Total Cache before 2.10.5, allowing arbitrary file writes to any existing directory on the server via the Disk Enhanced page cache.</description>
      <category>CVE-2026-18051</category>
    </item>
    <item>
      <title>CVE-2026-18366: Events Manager - Privilege Escalation</title>
      <link>https://1dayexploit.com/blog/cve-2026-18366-events-manager-privilege-escalation/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-18366-events-manager-privilege-escalation/</guid>
      <pubDate>Thu, 20 Aug 2026 12:00:00 GMT</pubDate>
      <description>CVE-2026-18366: Events Manager &lt; 7.4.1 allows unauthenticated privilege escalation to Administrator through broken access control - full site takeover.</description>
      <category>CVE-2026-18366</category>
    </item>
    <item>
      <title>CVE-2026-47686: vm2 Sandbox Escape - RCE</title>
      <link>https://1dayexploit.com/blog/cve-2026-47686-vm2-sandbox-escape-rce/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-47686-vm2-sandbox-escape-rce/</guid>
      <pubDate>Thu, 20 Aug 2026 12:00:00 GMT</pubDate>
      <description>CVE-2026-47686: vm2 Node.js sandbox vulnerable to escape via unsanitized Error.cause, allowing arbitrary code execution as the host process user.</description>
      <category>CVE-2026-47686</category>
    </item>
    <item>
      <title>CVE-2021-20295: QEMU SLiRP IPv6 OOB Read</title>
      <link>https://1dayexploit.com/blog/cve-2021-20295-qemu-slirp-ipv6-oob-read/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2021-20295-qemu-slirp-ipv6-oob-read/</guid>
      <pubDate>Wed, 19 Aug 2026 18:30:00 GMT</pubDate>
      <description>CVE-2021-20295: QEMU SLiRP trusts the guest IPv6 payload-length field, leaking up to 1.5 KB of hypervisor heap per ICMPv6 echo request. Information disclosure affecting QEMU 2.6.0-5.0.x.</description>
      <category>CVE-2021-20295</category>
    </item>
    <item>
      <title>CVE-2026-42945: NGINX Rift - Heap Buffer Overflow</title>
      <link>https://1dayexploit.com/blog/cve-2026-42945-nginx-rift-heap-overflow/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-42945-nginx-rift-heap-overflow/</guid>
      <pubDate>Wed, 19 Aug 2026 14:50:00 GMT</pubDate>
      <description>NGINX Rift (CVE-2026-42945): Heap buffer overflow in the rewrite module causes unauthenticated remote worker crash and denial of service.</description>
      <category>CVE-2026-42945</category>
    </item>
    <item>
      <title>CVE-2026-15571: Keycloak Account Linking Auth Bypass</title>
      <link>https://1dayexploit.com/blog/cve-2026-15571-keycloak-account-linking-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-15571-keycloak-account-linking-auth-bypass/</guid>
      <pubDate>Wed, 19 Aug 2026 11:39:32 GMT</pubDate>
      <description>CVE-2026-15571: Keycloak forgeable account-linking hash enables OIDC clients to bind external identities and achieve full account takeover via auth bypass.</description>
      <category>CVE-2026-15571</category>
    </item>
    <item>
      <title>CVE-2026-19598: Pods Auth Bypass - Privilege Escalation</title>
      <link>https://1dayexploit.com/blog/cve-2026-19598-pods-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-19598-pods-auth-bypass/</guid>
      <pubDate>Mon, 17 Aug 2026 14:30:00 GMT</pubDate>
      <description>CVE-2026-19598: Unauthenticated auth bypass in Pods WordPress plugin leading to administrator privilege escalation. Critical CVSS 9.8.</description>
      <category>CVE-2026-19598</category>
    </item>
    <item>
      <title>CVE-2026-56654: Gitea - Access Token Scope Escalation</title>
      <link>https://1dayexploit.com/blog/cve-2026-56654-gitea-token-scope-escalation/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-56654-gitea-token-scope-escalation/</guid>
      <pubDate>Mon, 17 Aug 2026 14:30:00 GMT</pubDate>
      <description>CVE-2026-56654: Gitea access token scope escalation (privilege escalation). A write:user token escalates to admin scope without a password.</description>
      <category>CVE-2026-56654</category>
    </item>
    <item>
      <title>CVE-2026-28185: Login with Google Auth Bypass</title>
      <link>https://1dayexploit.com/blog/cve-2026-28185-login-with-google-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-28185-login-with-google-auth-bypass/</guid>
      <pubDate>Mon, 17 Aug 2026 14:00:00 GMT</pubDate>
      <description>CVE-2026-28185: WordPress Login with Google auth bypass - unauthenticated administrator takeover via unverified email verification flag ignored in plugin &lt;= 1.4.2.</description>
      <category>CVE-2026-28185</category>
    </item>
    <item>
      <title>CVE-2019-10349: Jenkins Dependency Graph - Stored XSS</title>
      <link>https://1dayexploit.com/blog/cve-2019-10349-jenkins-dependency-graph-stored-xss/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2019-10349-jenkins-dependency-graph-stored-xss/</guid>
      <pubDate>Sat, 15 Aug 2026 15:30:00 GMT</pubDate>
      <description>Stored XSS (CVE-2019-10349) in Jenkins Dependency Graph Viewer Plugin &lt;= 0.13 lets attackers inject arbitrary JavaScript via unescaped job Display Names.</description>
      <category>CVE-2019-10349</category>
    </item>
    <item>
      <title>CVE-2026-34486: Tomcat Tribes RCE</title>
      <link>https://1dayexploit.com/blog/cve-2026-34486-tomcat-tribes-rce/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-34486-tomcat-tribes-rce/</guid>
      <pubDate>Sat, 15 Aug 2026 14:30:00 GMT</pubDate>
      <description>CVE-2026-34486 - Tomcat 10.1.53 RCE via EncryptInterceptor bypass in Tribes receiver. Unfiltered Java deserialization without authentication or credentials.</description>
      <category>CVE-2026-34486</category>
    </item>
  </channel>
</rss>
