<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>1dayexploit</title>
    <link>https://1dayexploit.com</link>
    <atom:link href="https://1dayexploit.com/rss.xml" rel="self" type="application/rss+xml"/>
    <description>Technical deep-dives into recently disclosed CVEs.</description>
    <language>en</language>
    <lastBuildDate>Tue, 07 Jul 2026 21:02:19 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-48611: phpBB - Auth Bypass</title>
      <link>https://1dayexploit.com/blog/cve-2026-48611-phpbb-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-48611-phpbb-auth-bypass/</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-48611 is a critical auth bypass in phpBB 3.3.0-3.3.16 enabling account takeover without knowing the victim's password. Single unauthenticated HTTP request, CVSS 9.8.</description>
      <category>CVE-2026-48611</category>
    </item>
    <item>
      <title>CVE-2026-42945: NGINX Heap Buffer Overflow</title>
      <link>https://1dayexploit.com/blog/cve-2026-42945-nginx-heap-buffer-overflow/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-42945-nginx-heap-buffer-overflow/</guid>
      <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-42945: heap buffer overflow in NGINX 0.6.27-1.30.0. Malicious HTTP requests trigger script engine state mismatch, leading to DoS or RCE.</description>
      <category>CVE-2026-42945</category>
    </item>
    <item>
      <title>CVE-2026-27960: OpenCTI Authentication Bypass via Hardcoded UUID</title>
      <link>https://1dayexploit.com/blog/cve-2026-27960-opencti-auth-bypass/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-27960-opencti-auth-bypass/</guid>
      <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-27960 in OpenCTI - Authentication bypass via hardcoded admin UUID allows unauthenticated RCE-equivalent access.</description>
      <category>CVE-2026-27960</category>
    </item>
    <item>
      <title>CVE-2026-7482 - Ollama Heap Out-of-Bounds Read</title>
      <link>https://1dayexploit.com/blog/cve-2026-7482-ollama-heap-oob-gguf/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/cve-2026-7482-ollama-heap-oob-gguf/</guid>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-7482: Ollama heap OOB read in GGUF loader leaks environment variables, API keys, and in-flight prompts. CVSS 9.1 CRITICAL. Affects &lt; 0.17.1.</description>
      <category>CVE-2026-7482</category>
    </item>
    <item>
      <title>Welcome to 1dayexploit</title>
      <link>https://1dayexploit.com/blog/welcome/</link>
      <guid isPermaLink="true">https://1dayexploit.com/blog/welcome/</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate>
      <description>A cyber security research hub publishing technical deep-dives into recent CVEs and security advisories.</description>
    </item>
  </channel>
</rss>
