A CVE is a claim. We turn claims into evidence.
1dayexploit is a cyber security research hub. Not a vendor, not a consultancy - a small group that builds tools, publishes what it finds, and gives the work away.
Most published vulnerabilities are a paragraph of prose and a severity score. Whether the thing actually works, what it takes to make it work, and whether the fix really closes it are all left to the reader. That gap is the reason we exist. We work the 1-day window: the interval between a patch landing and widespread exploitation, when defenders are racing to deploy and attackers are racing to reverse-engineer.
Proof, or nothing.
You will find here:
- Root cause analyses of recently disclosed vulnerabilities, traced through the source
- Patch diffs read line by line, and reverse engineering walkthroughs
- Proof-of-concept exploits, released post-patch
- Our own security advisories when we disclose a finding
You will not find:
- Unpatched zero-days, or anything for sale
- Novice-level content or commodity exploit walkthroughs
Evidence over assertion.
A finding is only published once it has been demonstrated. Our engine ÂLIM rebuilds a vulnerability in an isolated containerised lab, develops a working proof-of-concept, and runs it against both the vulnerable and the patched build - so the fix is verified, not assumed.
We also say plainly when something could not be reproduced, or only partly worked. A failed analysis is a result too, and hiding it would make everything else we publish worth less.
Everything we produce is free.
No product, no paywall, no lead capture. Analyses, write-ups and proof-of-concept code are published openly.
Patch first.
We do not sell vulnerabilities, share them with third parties, or publish exploits before a patch is available. Everything is released for research and educational use. We do not endorse or assist unauthorized use.
We give our work back to the databases, maintainers and researchers whose work we build on. Corrections to anything we have published are welcome and credited.