Identifier index
Verified CVE reproductions
Public CVE-backed security reproductions with runnable sandbox proof, affected package/version metadata, artifacts, and permanent REPRO IDs.
Popular records
Top viewed verified CVEs
Direct links to frequently viewed CVE entries, each connected to a runnable Pruva evidence record.
CVE-2026-63030 WordPress 7.0.1 pre-auth fresh-administrator chain to RCE CVE-2026-42533 NGINX ASLR-enabled network RCE CVE-2026-61511 vBulletin runtime template runMaths pre-auth RCE CVE-2026-5674 PipeWire sandbox escape via malicious library loading in PulseAudio compatibility layer CVE-2026-66066 Rails Active Storage variant processing arbitrary file read and potential RCE CVE-2026-33557 Apache Kafka SASL/OAUTHBEARER accepts unvalidated JWTs
196 CVE-backed records
Agent catalog CVE-2026-14537
REPRO-2026-00318 published
mcp-toolbox authorization bypass: unauthenticated tool invocation via direct HTTP API
CVE-2026-14537 high Security Known vulnerability github
googleapis/genai-toolbox
37m 46s Aug 1, 2026
CVE-2026-66066
REPRO-2026-00317 published
Rails Active Storage variant processing arbitrary file read and potential RCE
CVE-2026-66066 critical Security Known vulnerability github
rails/rails
148m 42s Aug 1, 2026
CVE-2026-39987
REPRO-2026-00316 published
marimo Pre-Auth RCE via Terminal WebSocket Authentication Bypass (/terminal/ws missing validate_auth)
CVE-2026-39987 critical Security Known vulnerability github
marimo
24m 19s Jul 30, 2026
CVE-2026-59726
REPRO-2026-00315 published
Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment
CVE-2026-59726 critical Security Known vulnerability npm
ruflo
34m 45s Jul 30, 2026
CVE-2026-27960
REPRO-2026-00314 published
OpenCTI authentication bypass via user impersonation
CVE-2026-27960 critical Security Known vulnerability docker
opencti
44m 34s Jul 30, 2026
CVE-2026-60004
REPRO-2026-00312 published
Gitea diffpatch Git hook installation leads to remote code execution
CVE-2026-60004 critical Security Known vulnerability github
go-gitea/gitea
30m 6s Jul 29, 2026
CVE-2026-55626
REPRO-2026-00311 published
xrdp Xvnc backend authentication issue on RHEL 9
CVE-2026-55626 high Security Known vulnerability github
neutrinolabs/xrdp
64m 30s Jul 29, 2026
CVE-2025-71334
REPRO-2026-00310 published
Flowise arbitrary file access via unvalidated chatflowId/chatId
CVE-2025-71334 critical Security Known vulnerability npm
FlowiseAI/Flowise
66m 57s Jul 28, 2026
CVE-2026-5674
REPRO-2026-00309 published
PipeWire sandbox escape via malicious library loading in PulseAudio compatibility layer
CVE-2026-5674 high Security Known vulnerability
pipewire (pipewire-pulse daemon)
88m 8s Jul 28, 2026
CVE-2026-42533
REPRO-2026-00308 published
NGINX ASLR-enabled network RCE
CVE-2026-42533 critical Security Known vulnerability github
nginx/nginx
71m 44s Jul 27, 2026
CVE-2026-61511
REPRO-2026-00307 published
vBulletin runtime template runMaths pre-auth RCE
CVE-2026-61511 critical Security Discovery hunt
vBulletin
139m 11s Jul 27, 2026
CVE-2026-66012
REPRO-2026-00305 published
SiYuan missing authorization in /mcp enables unauthenticated administrator takeover via Publish proxy
CVE-2026-66012 critical Security Known vulnerability github
siyuan
171m 57s Jul 27, 2026
CVE-2026-17496
REPRO-2026-00304 published
NoteGen chat preview XSS via unsanitized HTML rendering before 0.32.0
CVE-2026-17496 high Security Known vulnerability github
note-gen
78m 29s Jul 27, 2026
CVE-2026-16584
REPRO-2026-00303 published
AWS API MCP Server security policy bypass via startup initialization failure
CVE-2026-16584 high Security Known vulnerability pip
awslabs.aws-api-mcp-server
29m 52s Jul 27, 2026
CVE-2026-63720
REPRO-2026-00302 published
datamodel-code-generator code injection via customBasePath before 0.70.0
CVE-2026-63720 high Security Known vulnerability pip
datamodel-code-generator
13m 44s Jul 27, 2026
CVE-2026-66013
REPRO-2026-00300 published
OpenRemote console registration authentication bypass via known asset identifier
CVE-2026-66013 critical Security Known vulnerability github
openremote
35m 36s Jul 27, 2026
CVE-2026-63030
REPRO-2026-00294 published
WordPress 7.0.1 pre-auth fresh-administrator chain to RCE
CVE-2026-63030 critical Security
Variant found
Known vulnerability
WordPress Core
65m 17s Jul 19, 2026
CVE-2026-59826
REPRO-2026-00293 published
Metabase arbitrary code execution via unsafe H2 connection property validation bypass
CVE-2026-59826 critical Security
Variant found
Known vulnerability github
metabase/metabase
92m 57s Jul 17, 2026
CVE-2026-54466
REPRO-2026-00292 published
websocket-driver: message corruption via abuse of draft-WebSocket length headers
CVE-2026-54466 critical Security
Variant found
Known vulnerability npm
faye/websocket-driver-node
7m 28s Jul 16, 2026
CVE-2026-50289
REPRO-2026-00291 published
systeminformation networkInterfaces() Linux source-directive command injection
CVE-2026-50289 high Security
Variant found
Known vulnerability github
sebhildebrandt/systeminformation
14m 44s Jul 16, 2026
CVE-2026-58196
REPRO-2026-00290 published
ToolHive SSRF in remote MCP server authentication discovery
CVE-2026-58196 medium Security
Variant found
Known vulnerability github
github.com/stacklok/toolhive
43m 47s Jul 16, 2026
CVE-2026-55175
REPRO-2026-00289 published
Spinnaker Kustomize bake unsafe YAML tag processing leading to RCE
CVE-2026-55175 high Security
Variant found
Known vulnerability github
spinnaker/spinnaker
15m 51s Jul 15, 2026
CVE-2026-60102
REPRO-2026-00288 published
Horde VFS < 3.0.1 OS command injection via Horde_Vfs_Smb driver
CVE-2026-60102 high Security
Variant found
github
horde/vfs
12m 50s Jul 14, 2026
CVE-2026-39999
REPRO-2026-00287 published
Apache APISIX jwt-auth authentication bypass via algorithm confusion
CVE-2026-39999 critical Security
Variant found
github
apache/apisix
14m 33s Jul 14, 2026
CVE-2026-49844
REPRO-2026-00286 published
Log4j MapMessage emits invalid JSON for non-finite values
CVE-2026-49844 medium Security
Variant found
maven
org.apache.logging.log4j:log4j-api
11m 14s Jul 13, 2026
CVE-2026-4480
REPRO-2026-00285 published
Samba’s printing subsystem allows OS command injection via unescaped job description (%J), enabling remote code execution through crafted print jobs.
CVE-2026-4480 critical Security
Variant found
generic
samba-team/samba
28m 55s Jul 13, 2026
CVE-2026-52831
REPRO-2026-00283 published
Nuclio cron trigger shell command injection leading to RCE
CVE-2026-52831 critical Security
Variant found
go
github.com/nuclio/nuclio
89m 0s Jul 11, 2026
CVE-2025-24813
REPRO-2026-00282 published
Apache Tomcat partial PUT session deserialization RCE
CVE-2025-24813 critical Security maven
Apache Tomcat
42m 34s Jul 11, 2026
CVE-2026-33557
REPRO-2026-00281 published
Apache Kafka SASL/OAUTHBEARER accepts unvalidated JWTs
CVE-2026-33557 critical Security
Variant found
maven
Apache Kafka
44m 25s Jul 11, 2026
CVE-2026-50229
REPRO-2026-00280 published
Apache Tomcat examples app XSS in numguess.jsp
CVE-2026-50229 medium Security
Variant found
github
apache/tomcat
16m 6s Jul 9, 2026
CVE-2026-43825
REPRO-2026-00279 published
Apache OpenNLP SvmDoccatModel unsafe deserialization
CVE-2026-43825 high Security
Variant found
github
apache/opennlp
14m 59s Jul 9, 2026
CVE-2026-10536
REPRO-2026-00278 published
libcurl HTTP/2 stream-dependency tree use-after-free
CVE-2026-10536 critical Security
Variant found
github
curl/libcurl
22m 30s Jul 9, 2026
CVE-2026-33264
REPRO-2026-00277 published
Apache Airflow DAG author RCE via unrestricted import_string() in BaseSerialization.deserialize()
CVE-2026-33264 critical Security
Variant found
github
apache/airflow
16m 12s Jul 9, 2026
CVE-2026-41042
REPRO-2026-00276 published
Apache Gravitino unauthenticated H2 JDBC URL injection via testConnection API
CVE-2026-41042 critical Security
Variant found
github
apache/gravitino
22m 47s Jul 9, 2026
CVE-2026-34047
REPRO-2026-00275 published
Coolify terminal WebSocket endpoints lack proper authorization checks, allowing low-privileged members to access terminal functionality and achieve remote command execution on managed hosts.
CVE-2026-34047 critical Security
Variant found
Composer
coollabsio/coolify
44m 2s Jul 8, 2026
CVE-2026-53513
REPRO-2026-00274 published
@better-auth/sso <1.6.11 allows non-blind SSRF via unvalidated OIDC endpoint URLs during SSO provider registration, with potential account takeover when trustEmailVerified is enabled.
CVE-2026-53513 critical Security
Variant found
npm
@better-auth/sso
30m 49s Jul 8, 2026
CVE-2026-23698
REPRO-2026-00273 published
Vtiger CRM through 8.4.0 allows authenticated admin users to achieve remote code execution by uploading a crafted module ZIP that places PHP files in the web-accessible modules/ directory.
CVE-2026-23698 high Security
Variant found
other
Vtiger CRM
33m 54s Jul 8, 2026
CVE-2026-27823
REPRO-2026-00272 published
EGroupware contains an authorization bypass in SmallPartMediaRecorder::ajax_upload combined with arbitrary file write and file read primitives, enabling authenticated (or self-registered) attackers to overwrite header.inc.php and achieve remote code execution.
CVE-2026-27823 critical Security
Variant found
Composer
egroupware/egroupware
78m 4s Jul 8, 2026
CVE-2026-59800
REPRO-2026-00270 published
9router before 0.4.44 allows unauthenticated remote OS command execution via the /api/tunnel/tailscale-install endpoint by injecting shell commands in the sudoPassword field when sudo does not prompt for a password.
CVE-2026-59800 critical Security
Variant found
npm
9router (npm)
45m 53s Jul 8, 2026
CVE-2026-48908
REPRO-2026-00269 published
SP Page Builder for Joomla allows unauthenticated arbitrary file upload via asset.uploadCustomIcon, enabling PHP upload and remote code execution.
CVE-2026-48908 critical Security
Variant found
Joomla extension
SP Page Builder (com_sppagebuilder)
77m 51s Jul 8, 2026
CVE-2026-55255
REPRO-2026-00268 published
Langflow’s /api/v1/responses endpoint contains an IDOR that lets any authenticated user execute another user’s flow by supplying the victim’s flow UUID.
CVE-2026-55255 critical Security
Variant found
pip
langflow (pip)
28m 29s Jul 8, 2026
CVE-2026-40022
REPRO-2026-00267 published
Apache Camel embedded HTTP/management servers can bypass authentication on subpaths when a non-root context path is configured, allowing unauthenticated access to protected routes and management endpoints.
CVE-2026-40022 high Security
Variant found
maven
org.apache.camel:camel-platform-http-main
20m 26s Jul 7, 2026
CVE-2026-20253
REPRO-2026-00266 published
Unauthenticated arbitrary file operations in Splunk Enterprise PostgreSQL sidecar service (SVD-2026-0603)
CVE-2026-20253 critical Security
Variant found
github
splunk/splunk
63m 18s Jul 7, 2026
CVE-2024-26582
REPRO-2026-00265 published
Linux kernel kTLS Use-After-Free
CVE-2024-26582 high Security
Variant found
github
torvalds/linux
49m 32s Jul 7, 2026
CVE-2026-40047
REPRO-2026-00264 published
Apache Camel camel-docling improperly validates custom CLI arguments, enabling argument injection and path traversal when untrusted data is mapped into docling invocation headers.
CVE-2026-40047 critical Security
Variant found
Maven
apache/camel
41m 23s Jul 7, 2026
CVE-2026-33630
REPRO-2026-00263 published
c-ares CVE-2026-33630 RCE primitive construction from confirmed remote UAF
CVE-2026-33630 high Security
Variant found
c
c-ares/c-ares
54m 27s Jul 7, 2026
CVE-2026-48282
REPRO-2026-00262 published
ColdFusion 2025 Lockdown: open-RDS unauth direct-Tomcat absolute-path FILEIO RCE confirmed
CVE-2026-48282 critical Security
Adobe ColdFusion
80m 25s Jul 7, 2026
CVE-2026-42271
REPRO-2026-00261 published
BerriAI LiteLLM SQL injection
CVE-2026-42271 high Security
Variant found
pip
BerriAI LiteLLM
168m 42s Jul 7, 2026
CVE-2026-48939
REPRO-2026-00259 published
iCagenda unauthenticated file upload RCE in public event submission form
CVE-2026-48939 critical Security
Variant found
joomla
iCagenda
107m 17s Jul 6, 2026
CVE-2026-32833
REPRO-2026-00258 published
Cudy LT300 3.0 OS command injection
CVE-2026-32833 high Security
Variant found
firmware
Cudy LT300 V3 firmware
93m 59s Jul 6, 2026
CVE-2026-49297
REPRO-2026-00257 published
Apache Airflow Google provider path traversal via GCS object names
CVE-2026-49297 high Security
Variant found
pip
apache-airflow-providers-google
56m 55s Jul 6, 2026
CVE-2026-57518
REPRO-2026-00256 published
Pagekit CMS privilege escalation leading to RCE
CVE-2026-57518 high Security
Variant found
github
pagekit/pagekit
23m 15s Jul 6, 2026
CVE-2026-58453
REPRO-2026-00255 published
JAIOTlink C492A-W6 Wi‑Fi IP camera firmware accepts default admin credentials (blank password) over HTTP Basic auth, enabling network‑adjacent attackers to access snapshots and privileged APIs.
CVE-2026-58453 critical Security
Variant found
firmware
jingwenyi/SmartCamera (Anyka N1
29m 42s Jul 6, 2026
CVE-2026-58169
REPRO-2026-00254 published
Vibe-Trading DNS rebinding authentication bypass leading to RCE
CVE-2026-58169 high Security
Variant found
Vibe-Trading (pip: vibe-trading-ai)
18m 8s Jul 6, 2026
CVE-2026-57947
REPRO-2026-00253 published
Pinpoint through 3.1.0 allows authenticated users to register internal webhook URLs, leading to SSRF when alarm webhooks are delivered.
CVE-2026-57947 medium Security
Variant found
maven
pinpoint-apm/pinpoint
59m 13s Jul 6, 2026
CVE-2026-5524
REPRO-2026-00252 published
Divi Form Builder WordPress plugin allows unauthenticated arbitrary file upload via user-controlled acceptFileTypes, leading to RCE by uploading executable PHP extensions and accessing them in /wp-content/uploads/de_fb_uploads/.
CVE-2026-5524 critical Security wordpress
divi-form-builder
20m 35s Jul 6, 2026
CVE-2026-54849
REPRO-2026-00251 published
Premmerce Wishlist for WooCommerce unauthenticated SQL injection
CVE-2026-54849 critical Security
Variant found
Premmerce/Premmerce Wishlist for WooCommerce
27m 26s Jul 6, 2026
CVE-2026-58377
REPRO-2026-00250 published
JeecgBoot broken access control privilege escalation
CVE-2026-58377 high Security
Variant found
github
jeecgboot/JeecgBoot
31m 46s Jul 6, 2026
CVE-2026-57527
REPRO-2026-00249 published
ZAP ViewState add-on insecure deserialization RCE
CVE-2026-57527 high Security
Variant found
github
zaproxy/zap-extensions
26m 16s Jul 6, 2026
CVE-2026-50195
REPRO-2026-00248 published
containerd CRI checkpoint import RCE
CVE-2026-50195 critical Security
Variant found
github.com/containerd/containerd/v2
39m 23s Jul 6, 2026
CVE-2026-49869
REPRO-2026-00247 published
Kestra unauthenticated RCE via AuthenticationFilter path bypass
CVE-2026-49869 critical Security
Variant found
io.kestra:kestra (Kestra OSS)
26m 25s Jul 6, 2026
CVE-2026-49119
REPRO-2026-00246 published
Gradio FileExplorer path traversal
CVE-2026-49119 high Security
Variant found
github
gradio-app/gradio
21m 20s Jul 6, 2026
CVE-2026-34594
REPRO-2026-00245 published
Coolify authenticated command injection in Destination Network Management
CVE-2026-34594 high Security
Variant found
coollabsio/coolify
50m 51s Jul 6, 2026
CVE-2026-23537
REPRO-2026-00244 published
Feast Feature Server unauthenticated arbitrary file write to RCE
CVE-2026-23537 critical Security
Variant found
github
feast-dev/feast
37m 2s Jul 6, 2026
CVE-2026-11800
REPRO-2026-00243 published
Keycloak JWT algorithm confusion privilege escalation
CVE-2026-11800 high Security
Variant found
github
keycloak/keycloak
46m 0s Jul 6, 2026
CVE-2026-11387
REPRO-2026-00242 published
SMS Alert WordPress plugin <= 3.9.5 allows unauthenticated attackers to change a user’s email and reset their password, leading to account takeover and privilege escalation when OTP password reset verification is enabled.
CVE-2026-11387 critical Security
Variant found
WordPress plugin (hosted on WordPress.org SVN, not GitHub)
sms-alert
22m 56s Jul 6, 2026
CVE-2026-10835
REPRO-2026-00241 published
SALESmanago & Leadoo WordPress plugin SQL injection
CVE-2026-10835 high Security
Variant found
Unknown/SALESmanago & Leadoo
50m 2s Jul 6, 2026
CVE-2026-10129
REPRO-2026-00240 published
Langflow OSS SSRF and privilege escalation
CVE-2026-10129 high Security
Variant found
langflow/langflow
56m 49s Jul 6, 2026
CVE-2026-8441
REPRO-2026-00239 published
WP Review Slider Pro SQL injection
CVE-2026-8441 high Security
Variant found
https://wpreviewslider.com//WP Review Slider Pro
42m 0s Jul 6, 2026
CVE-2026-58166
REPRO-2026-00238 published
OpenBMB ChatDev unauthenticated path traversal file upload
CVE-2026-58166 critical Security
Variant found
github
OpenBMB/ChatDev
28m 27s Jul 6, 2026
CVE-2026-58165
REPRO-2026-00237 published
OpenZiti privilege escalation via overpermissive enrollment creation
CVE-2026-58165 high Security
Variant found
OpenZiti
22m 39s Jul 6, 2026
CVE-2026-58138
REPRO-2026-00236 published
Orkes Conductor unauthenticated RCE via inline script evaluators
CVE-2026-58138 critical Security
Variant found
conductor-oss/conductor (Orkes Conductor OSS)
24m 53s Jul 6, 2026
CVE-2026-58126
REPRO-2026-00235 published
PACSgear PACS Scan unauthenticated remote code execution
CVE-2026-58126 critical Security
Variant found
Hyland/PACSgear PACS Scan
64m 7s Jul 6, 2026
CVE-2026-57624
REPRO-2026-00234 published
Blocksy Companion Pro unauthenticated remote code execution
CVE-2026-57624 critical Security
Variant found
Creative Themes/Blocksy Companion Pro
37m 0s Jul 6, 2026
CVE-2026-56700
REPRO-2026-00233 published
Grav CMS unsafe deserialization and command injection RCE
CVE-2026-56700 critical Security
Variant found
getgrav/grav (Composer)
53m 20s Jul 6, 2026
CVE-2026-56290
REPRO-2026-00232 published
Page Builder CK unauthenticated arbitrary file upload to RCE
CVE-2026-56290 critical Security
Variant found
joomlack/page_builder_ck
23m 44s Jul 6, 2026
CVE-2026-50052
REPRO-2026-00231 published
HTTP/2 request smuggling in Vinyl Cache and Varnish Cache (VSV00019)
CVE-2026-50052 low Security
Variant found
github
varnish/varnish
28m 5s Jul 6, 2026
CVE-2026-54823
REPRO-2026-00230 published
Widget Options WordPress plugin contributor remote code execution
CVE-2026-54823 critical Security
Variant found
MarketingFire/Widget Options
28m 45s Jul 6, 2026
CVE-VINEXT-CIVETWEB-PUT-SSI-RCE
REPRO-2026-00229 published
CivetWeb PUT + SSI #exec RCE
CVE-VINEXT-CIVETWEB-PUT-SSI-RCE high Security
Variant found
github
civetweb/civetweb
34m 27s Jul 4, 2026
CVE-2026-48611
REPRO-2026-00223 published
phpBB authentication bypass/account hijacking via OAuth login-link flow with arbitrary auth_provider=apache
CVE-2026-48611 critical Security
Variant found
github
phpbb/phpbb
22m 9s Jul 4, 2026
CVE-2026-48558
REPRO-2026-00222 published
SimpleHelp OIDC authentication accepts unsigned/forged ID tokens, enabling remote authentication bypass and possible MFA bypass in versions 5.5.15 and earlier and 6.0 prereleases prior to the fixed release.
CVE-2026-48558 critical Security
Variant found
other (commercial, Java-based server application)
SimpleHelp
94m 25s Jul 4, 2026
CVE-2026-31694
REPRO-2026-00221 published
Linux kernel FUSE readdir cache out-of-bounds write
CVE-2026-31694 high Security
Variant found
Linux kernel (FUSE subsystem)
63m 5s Jul 3, 2026
CVE-2026-59092
REPRO-2026-00220 published
JuiceFS through 1.3.1 exposes debug/metrics endpoints via shared http.DefaultServeMux, enabling authentication bypass and leakage of sensitive metadata connection strings, with potential DoS via profiling handlers.
CVE-2026-59092 high Security
Variant found
go
JuiceFS (juicedata/juicefs)
14m 46s Jul 3, 2026
CVE-2026-58466
REPRO-2026-00219 published
AutoBangumi before 3.2.8 seeds a default admin account on empty databases, allowing unauthenticated users to log in with publicly known default credentials and gain full control.
CVE-2026-58466 critical Security
Variant found
standalone application (Python/FastAPI)
EstrellaXD/Auto_Bangumi
14m 56s Jul 3, 2026
CVE-2026-52830
REPRO-2026-00218 published
fast-mcp-telegram <=0.19.0 allows bearer token path traversal to authenticate as the default telegram.session, bypassing reserved session name protections and enabling unauthorized access to Telegram MCP tools.
CVE-2026-52830 critical Security
Variant found
pip
fast-mcp-telegram
17m 51s Jul 3, 2026
CVE-2026-49352
REPRO-2026-00217 published
9router hardcoded default fallback JWT secret allows authentication bypass
CVE-2026-49352 critical Security
Variant found
github
decolua/9router
13m 50s Jul 3, 2026
CVE-2026-43503
REPRO-2026-00212 published
DirtyClone Linux kernel page-cache corruption privilege escalation
CVE-2026-43503 high Security
Variant found
linux
Linux kernel
70m 55s Jul 3, 2026
CVE-2026-43456
REPRO-2026-00211 published
Linux kernel bonding can inherit header_ops from non‑Ethernet slaves (e.g., GRE), causing type confusion and kernel crashes when dev_hard_header() is invoked on the bond device.
CVE-2026-43456 high Security
Variant found
linux
Linux kernel (bonding driver)
64m 59s Jul 3, 2026
CVE-2026-48816
REPRO-2026-00210 published
sigstore-js Insufficient Verification of Data Authenticity
CVE-2026-48816 medium Security
Variant found
github
sigstore/sigstore-js
18m 54s Jul 2, 2026
CVE-2026-54502
REPRO-2026-00209 published
Oj Ruby gem stack buffer overflow via large :indent value
CVE-2026-54502 medium Security
Variant found
Ruby
oj
18m 33s Jul 2, 2026
CVE-2026-54500
REPRO-2026-00208 published
Oj Ruby gem uninitialized stack memory leak via long JSON keys
CVE-2026-54500 medium Security
Variant found
oj (Optimized JSON) Ruby gem
20m 41s Jul 2, 2026
CVE-2026-14198
REPRO-2026-00207 published
@fastify/middie encoded slash bypass on parameterized middleware paths
CVE-2026-14198 critical Security
Variant found
@fastify/middie
9m 46s Jul 2, 2026
CVE-2026-41579
REPRO-2026-00206 published
runc symlink deletion via malicious /dev symlink in container image
CVE-2026-41579 low Security
Variant found
github.com/opencontainers/runc
25m 21s Jul 2, 2026
CVE-2026-49857
REPRO-2026-00205 published
auth-fetch-mcp SSRF via IPv4-mapped IPv6 loopback bypass
CVE-2026-49857 high Security
Variant found
npm
ymw0407/auth-fetch-mcp
17m 11s Jul 2, 2026
CVE-2026-11380
REPRO-2026-00203 published
JetWidgets For Elementor Stored XSS via Animated Box animation_effect
CVE-2026-11380 medium Security
Variant found
jetmonsters/jetwidgets-for-elementor
29m 27s Jul 2, 2026
CVE-2026-4983
REPRO-2026-00202 published
Open VSX Registry serves HTML inline enabling session/token exfiltration
CVE-2026-4983 medium Security
Variant found
Eclipse Open VSX (openvsx server)
36m 21s Jul 2, 2026
CVE-2026-33017
REPRO-2026-00201 published
Unauthenticated RCE in Langflow via public flow build endpoint
CVE-2026-33017 critical Security
Variant found
pip
langflow
25m 8s Jul 2, 2026
CVE-2024-23897
REPRO-2026-00200 published
Jenkins CLI arbitrary file read via @ argument expansion
CVE-2024-23897 critical Security generic
jenkins
21m 31s Jul 2, 2026
CVE-2024-23334
REPRO-2026-00199 published
aiohttp static file directory traversal via follow_symlinks
CVE-2024-23334 high Security pip
aiohttp
11m 4s Jul 2, 2026
CVE-2025-29927
REPRO-2026-00198 published
Next.js middleware authorization bypass via x-middleware-subrequest
CVE-2025-29927 critical Security npm
next
37m 24s Jul 2, 2026
CVE-2025-55182
REPRO-2026-00196 published
React Server Components Flight protocol remote code execution
CVE-2025-55182 critical Security npm
react-server-dom-webpack
34m 46s Jul 2, 2026
CVE-2025-30208
REPRO-2026-00195 published
Vite dev server access control can be bypassed using crafted query strings, allowing arbitrary file reads via the @fs handler when the dev server is exposed to the network.
CVE-2025-30208 medium Security npm
vite
23m 11s Jul 1, 2026
CVE-2026-8054
REPRO-2026-00194 published
Unauthenticated SQL injection in dotCMS Publish Audit API
CVE-2026-8054 critical Security
Variant found
github
dotCMS/core
116m 7s Jul 1, 2026
CVE-2026-35025
REPRO-2026-00193 published
ProFTPD ACL bypass via /proc/self/root path prefix in RNFR
CVE-2026-35025 high Security
Variant found
github
proftpd/proftpd
88m 18s Jul 1, 2026
CVE-2026-52813
REPRO-2026-00192 published
Gogs path traversal in organization name results in RCE through Git hooks
CVE-2026-52813 critical Security
Variant found
github
gogs/gogs
29m 54s Jul 1, 2026
CVE-2026-55200
REPRO-2026-00186 published
libssh2 via curl: malformed SSH packet length crashes SFTP client
CVE-2026-55200 critical Security c
libssh2
11m 23s Jun 25, 2026
CVE-2026-7474
REPRO-2026-00185 published
HashiCorp Nomad: path traversal in host volume plugin loader → client-host RCE
CVE-2026-7474 high Security
Variant found
go
nomad
48m 9s May 28, 2026
CVE-2026-5199
REPRO-2026-00184 published
Temporal Server: batcher worker cross-namespace authorization bypass (BatchActivityWithProtobuf)
CVE-2026-5199 low Security
Variant found
go
temporal
72m 49s May 28, 2026
CVE-2026-33721
REPRO-2026-00183 published
MapServer: heap-buffer-overflow in SLD Categorize parser (msSLDParseRasterSymbolizer)
CVE-2026-33721 medium Security
Variant found
c
mapserver
14m 33s May 28, 2026
CVE-2026-5466
REPRO-2026-00173 published
wolfSSL: ECCSI universal signature forgery via missing scalar range check
CVE-2026-5466 high Security
Variant found
source
wolfssl
16m 28s May 28, 2026
CVE-2026-5479
REPRO-2026-00172 published
wolfSSL: EVP ChaCha20-Poly1305 decryption returns plaintext without verifying authentication tag
CVE-2026-5479 high Security
Variant found
source
wolfssl
12m 46s May 28, 2026
CVE-2026-27654
REPRO-2026-00171 published
nginx WebDAV: heap-buffer-overflow in COPY/MOVE with alias directive
CVE-2026-27654 high Security
Variant found
source
nginx
21m 40s May 28, 2026
CVE-2026-32316
REPRO-2026-00170 published
jq: integer overflow in jv_string_concat triggers heap buffer overflow on large strings
CVE-2026-32316 high Security
Variant found
github
jq
32m 33s May 28, 2026
CVE-2026-40900
REPRO-2026-00169 published
DataEase: stacked-query SQL injection via previewSql with allowMultiQueries
CVE-2026-40900 high Security
Variant found
github
dataease
58m 29s May 26, 2026
CVE-2026-23958
REPRO-2026-00168 published
DataEase: authentication bypass via password-derived HMAC JWT signing key
CVE-2026-23958 critical Security
Variant found
github
dataease
100m 11s May 25, 2026
CVE-2026-40901
REPRO-2026-00167 published
DataEase: Quartz JobStore Java deserialization RCE via QRTZ_JOB_DETAILS
CVE-2026-40901 high Security github
dataease
179m 9s May 25, 2026
CVE-2026-40899
REPRO-2026-00165 published
DataEase: JDBC parameter blocklist bypass via Lombok @Data setter exposure
CVE-2026-40899 medium Security
Variant found
github
dataease
111m 23s May 25, 2026
CVE-2026-42796
REPRO-2026-00160 published
Arelle: unauthenticated RCE via /rest/configure plugins URL parameter
CVE-2026-42796 critical Security
Variant found
pip
arelle
48m 18s May 23, 2026
CVE-2026-32740
REPRO-2026-00159 published
libheif: heap-buffer-overflow write decoding 1x4 grid of odd-height tiles
CVE-2026-32740 high Security
Variant found
c
libheif
41m 53s May 23, 2026
CVE-2026-42091
REPRO-2026-00158 published
goshs: PUT upload accepts cross-origin requests without CSRF token
CVE-2026-42091 medium Security
Variant found
go
github.com/patrickhener/goshs
35m 17s May 23, 2026
CVE-2026-30246
REPRO-2026-00157 published
Fiber v3: cache middleware key collision leaks responses across different query strings
CVE-2026-30246 medium Security
Variant found
go
github.com/gofiber/fiber/v3
27m 11s May 23, 2026
CVE-2026-39850
REPRO-2026-00156 published
Yii2: local file inclusion via View::renderPhpFile extract() of caller-controlled params
CVE-2026-39850 high Security
Variant found
composer
yiisoft/yii2
15m 11s May 23, 2026
CVE-2026-44471
REPRO-2026-00155 published
gitoxide (gix-fs): symlink worktree escape on checkout writes files outside the worktree
CVE-2026-44471 high Security
Variant found
cargo
gix-fs
33m 22s May 22, 2026
CVE-2026-35397
REPRO-2026-00153 published
Jupyter Server: path traversal via faulty startswith() root containment check
CVE-2026-35397 high Security
Variant found
pip
jupyter-server
25m 14s May 22, 2026
CVE-2026-42574
REPRO-2026-00152 published
apko: symlink-following path traversal writes files outside the build root
CVE-2026-42574 high Security
Variant found
go
apko
20m 23s May 22, 2026
CVE-2026-24425
REPRO-2026-00151 published
Twig: sandbox bypass via SourcePolicy filter check enables arbitrary PHP callables
CVE-2026-24425 high Security
Variant found
composer
twig/twig
13m 7s May 22, 2026
CVE-2026-34084
REPRO-2026-00150 published
PhpSpreadsheet: SSRF via unsafe stream wrapper in IOFactory::load()
CVE-2026-34084 critical Security
Variant found
composer
phpoffice/phpspreadsheet
12m 53s May 22, 2026
CVE-2026-44340
REPRO-2026-00149 published
PraisonAI: ZipSlip path traversal via unchecked tar symlink linkname in _safe_extractall
CVE-2026-44340 high Security
Variant found
pip
praisonai
17m 42s May 22, 2026
CVE-2026-33079
REPRO-2026-00148 published
Mistune: ReDoS via catastrophic backtracking in LINK_TITLE_RE
CVE-2026-33079 high Security
Variant found
pip
mistune
14m 50s May 22, 2026
CVE-2026-25765
REPRO-2026-00147 published
Faraday: SSRF via protocol-relative URL overriding base authority
CVE-2026-25765 medium Security
Variant found
rubygems
faraday
10m 15s May 22, 2026
CVE-2026-6322
REPRO-2026-00146 published
fast-uri: host confusion via percent-encoded authority delimiter in normalize()
CVE-2026-6322 high Security
Variant found
npm
fast-uri
10m 18s May 22, 2026
CVE-2026-6321
REPRO-2026-00145 published
fast-uri: path traversal via percent-encoded segments decoded before normalization
CVE-2026-6321 high Security
Variant found
npm
fast-uri
10m 8s May 22, 2026
CVE-2026-46364
REPRO-2026-00144 published
phpMyFAQ: unauthenticated SQL injection via User-Agent header in captcha API
CVE-2026-46364 critical Security
Variant found
composer
thorsten/phpmyfaq
62m 14s May 22, 2026
CVE-2026-25244
REPRO-2026-00143 published
@wdio/browserstack-service: OS command injection via crafted git branch name
CVE-2026-25244 critical Security
Variant found
npm
@wdio/browserstack-service
59m 49s May 22, 2026
CVE-2026-32738
REPRO-2026-00142 published
libheif: integer underflow out-of-bounds read crash via crafted HEIF stsc box
CVE-2026-32738 medium Security
Variant found
c
libheif
50m 30s May 22, 2026
CVE-2026-45232
REPRO-2026-00141 published
rsync: off-by-one out-of-bounds stack write in establish_proxy_connection
CVE-2026-45232 low Security
Variant found
c
rsync
29m 29s May 22, 2026
CVE-2026-37281
REPRO-2026-00140 published
zenshin: OS command injection in /stream-to-vlc url query parameter
CVE-2026-37281 critical Security
Variant found
zenshin
28m 3s May 22, 2026
CVE-2026-44699
REPRO-2026-00139 published
libjwt: JWT algorithm-confusion authentication bypass via RSA JWK without alg
CVE-2026-44699 critical Security
Variant found
c
libjwt
13m 26s May 22, 2026
CVE-2026-32871
REPRO-2026-00138 published
FastMCP: path traversal to authenticated SSRF in OpenAPIProvider _build_url()
CVE-2026-32871 critical Security
Variant found
pip
fastmcp
37m 15s May 22, 2026
CVE-2026-8813
REPRO-2026-00137 published
ExifReader: unbounded memory amplification DoS via crafted ICC mluc tag
CVE-2026-8813 high Security
Variant found
npm
exifreader
35m 45s May 22, 2026
CVE-2026-45539
REPRO-2026-00136 published
Microsoft APM: arbitrary file disclosure via symlink-following on apm install
CVE-2026-45539 high Security
Variant found
pip
apm
29m 1s May 22, 2026
CVE-2026-8657
REPRO-2026-00135 published
jsondiffpatch: prototype pollution via crafted delta in patch()
CVE-2026-8657 high Security
Variant found
npm
jsondiffpatch
23m 26s May 22, 2026
CVE-2025-13465
REPRO-2026-00134 published
lodash: prototype pollution in _.unset/_.omit deletes global prototype methods
CVE-2025-13465 medium Security
Variant found
npm
lodash
29m 27s May 22, 2026
CVE-2026-9082
REPRO-2026-00133 published
Drupal core: unauthenticated SQL injection via JSON:API filter array keys
CVE-2026-9082 critical Security
Variant found
composer
drupal/core
21m 27s May 22, 2026
CVE-2025-0520
REPRO-2026-00132 published
ShowDoc Unauthenticated File Upload RCE via deprecated ThinkPHP syntax
CVE-2025-0520 critical Security
Variant found
github
showdoc/showdoc
139m 41s Apr 14, 2026
CVE-2026-34486
REPRO-2026-00131 published
Apache Tomcat EncryptInterceptor Bypass via CVE-2026-29146 Fix Error - Missing Encryption of Sensitive Data
CVE-2026-34486 high Security
Variant found
Apache Tomcat
19m 38s Apr 14, 2026
CVE-2026-5463
REPRO-2026-00130 published
pymetasploit3 command injection
CVE-2026-5463 high Security
Variant found
PyPI
DanMcInerney/pymetasploit3
36m 8s Apr 4, 2026
CVE-2026-34742
REPRO-2026-00129 published
Go MCP SDK DNS Rebinding - Server-Side Request Forgery on AI Infrastructure
CVE-2026-34742 high Security
Variant found
Go module
github.com/modelcontextprotocol/go-sdk
38m 55s Apr 4, 2026
CVE-2026-34752
REPRO-2026-00128 published
Haraka Mail Server DoS via __proto__ prototype pollution in email headers
CVE-2026-34752 high Security
Variant found
github
npm/Haraka
17m 5s Apr 4, 2026
CVE-2026-34441
REPRO-2026-00127 published
cpp-httplib HTTP Request Smuggling via Unconsumed GET Request Body
CVE-2026-34441 medium Security
Variant found
github
yhirose/cpp-httplib
61m 29s Apr 4, 2026
CVE-2026-5245
REPRO-2026-00126 published
Cesanta Mongoose mDNS Stack Buffer Overflow - Remote Code Execution PoC
CVE-2026-5245 medium Security
Variant found
github
cesanta/mongoose
53m 53s Apr 2, 2026
CVE-2026-27876
REPRO-2026-00125 published
Grafana SQL Expressions RCE
CVE-2026-27876 critical Security
Variant found
github
grafana/grafana
59m 16s Apr 1, 2026
CVE-2026-34714
REPRO-2026-00124 published
Vim modeline handling for the tabpanel option allows sandbox escape via autocmd_add, enabling OS command execution when opening a crafted file.
CVE-2026-34714 critical Security
Variant found
github
Vim
19m 38s Apr 1, 2026
CVE-2026-24747
REPRO-2026-00119 published
PyTorch: weights_only Unpickler RCE via SETITEM Type Confusion
CVE-2026-24747 high Security
Variant found
pip
torch
48m 8s Mar 2, 2026
CVE-2026-21518
REPRO-2026-00118 published
cve-2026-21518
CVE-2026-21518 high Security
40m 34s Feb 21, 2026
CVE-2026-27203
REPRO-2026-00115 published
eBay MCP Server Environment Variable Injection via Crafted Prompts
CVE-2026-27203 high Security npm
@anthropic-ai/ebay-mcp-server
11m 39s Feb 20, 2026
CVE-2026-27194
REPRO-2026-00114 published
D-Tale Remote Code Execution via Custom Filter Input
CVE-2026-27194 critical Security pip
dtale
11m 53s Feb 20, 2026
CVE-2026-27192
REPRO-2026-00113 published
Feathers OAuth Authorization Header Leak to Third-Party
CVE-2026-27192 high Security npm
@feathersjs/authentication-oauth
7m 45s Feb 20, 2026
CVE-2026-27197
REPRO-2026-00112 published
Statamic CMS Stored XSS via Markdown Fieldtype
CVE-2026-27197 critical Security composer
statamic/cms
7m 48s Feb 20, 2026
CVE-2026-27198
REPRO-2026-00111 published
Formwork CMS Improper Privilege Management in User Creation
CVE-2026-27198 high Security composer
getformwork/formwork
12m 42s Feb 20, 2026
CVE-2026-27190
REPRO-2026-00110 published
Deno Command Injection via Incomplete Metacharacter Blocklist
CVE-2026-27190 high Security rust
deno
10m 5s Feb 20, 2026
CVE-2026-27191
REPRO-2026-00109 published
Feathers OAuth Open Redirect Account Takeover
CVE-2026-27191 medium Security npm
@feathersjs/authentication-oauth
12m 54s Feb 20, 2026
CVE-2026-27206
REPRO-2026-00108 published
Zumba JSON Serializer PHP Object Injection
CVE-2026-27206 high Security composer
zumba/json-serializer
11m 26s Feb 20, 2026
CVE-2026-27212
REPRO-2026-00107 published
Swiper Prototype Pollution
CVE-2026-27212 high Security npm
swiper
10m 21s Feb 20, 2026
CVE-2026-27013
REPRO-2026-00105 published
Fabric.js: Stored XSS via SVG Export
CVE-2026-27013 high Security npm
fabric
16m 24s Feb 19, 2026
CVE-2026-26280
REPRO-2026-00104 published
systeminformation: Command Injection via WiFi Interface Parameter
CVE-2026-26280 high Security npm
systeminformation
19m 36s Feb 19, 2026
CVE-2026-25755
REPRO-2026-00103 published
jsPDF: PDF Object Injection via Unsanitized addJS Input
CVE-2026-25755 high Security npm
jspdf
14m 30s Feb 19, 2026
CVE-2026-25940
REPRO-2026-00102 published
jsPDF: PDF Injection in AcroForm RadioButton allows JS Execution
CVE-2026-25940 high Security npm
jspdf
23m 38s Feb 19, 2026
CVE-2026-26990
REPRO-2026-00101 published
LibreNMS: Time-Based Blind SQL Injection in address-search
CVE-2026-26990 high Security composer
librenms/librenms
11m 33s Feb 19, 2026
CVE-2026-26318
REPRO-2026-00100 published
systeminformation: Command Injection via locate Output
CVE-2026-26318 high Security npm
systeminformation
18m 44s Feb 19, 2026
CVE-2026-26030
REPRO-2026-00099 published
Semantic Kernel: RCE via InMemoryVectorStore Filter
CVE-2026-26030 critical Security pip
semantic-kernel
25m 13s Feb 19, 2026
CVE-2026-25881
REPRO-2026-00098 published
SandboxJS: Host Prototype Pollution via Array Intermediary (Sandbox Escape)
CVE-2026-25881 critical Security npm
@nyariv/sandboxjs
16m 1s Feb 19, 2026
CVE-2026-1774
REPRO-2026-00097 published
CASL Ability: Prototype Pollution via Condition Handling
CVE-2026-1774 critical Security npm
@casl/ability
6m 19s Feb 19, 2026
CVE-2026-26190
REPRO-2026-00096 published
Milvus: Unauthenticated Access to Restful API on Metrics Port Leading to System Compromise
CVE-2026-26190 critical Security go
github.com/milvus-io/milvus
16m 18s Feb 19, 2026
CVE-2026-26273
REPRO-2026-00095 published
Known CMS: Account Takeover via Password Reset Token Leakage
CVE-2026-26273 critical Security composer
idno/known
17m 40s Feb 19, 2026
CVE-2026-26216
REPRO-2026-00093 published
Crawl4AI: Remote Code Execution in Docker API via Hooks Parameter
CVE-2026-26216 critical Security pip
Crawl4AI
10m 34s Feb 19, 2026
CVE-2026-25544
REPRO-2026-00092 published
Payload CMS: Blind SQL Injection in JSON/RichText Queries via Drizzle Adapters
CVE-2026-25544 critical Security npm
@payloadcms/drizzle
15m 33s Feb 19, 2026
CVE-2026-26980
REPRO-2026-00091 published
Ghost CMS: Unauthenticated SQL Injection in Content API Slug Filter
CVE-2026-26980 critical Security npm
ghost
4m 15s Feb 19, 2026
CVE-2025-8088
REPRO-2026-00090 published
WinRAR ADS Path Traversal — Arbitrary Code Execution via Crafted Archive (CVE-2025-8088)
CVE-2025-8088 high Security
123m 42s Feb 17, 2026
CVE-2026-26007
REPRO-2026-00089 published
pyca/cryptography SECT curve public key parsing lacks subgroup validation, enabling small-subgroup attacks that leak ECDH private key bits and allow ECDSA signature forgery.
CVE-2026-26007 medium Security
Variant found
cryptography (pip)
6m 32s Feb 15, 2026
CVE-2026-23906
REPRO-2026-00087 published
Apache Druid basic security LDAP authenticator can be bypassed when the LDAP server allows anonymous binds, permitting login with any existing username and an empty password.
CVE-2026-23906 critical Security
Variant found
Maven
org.apache.druid.extensions:druid-basic-security
48m 55s Feb 13, 2026
CVE-2026-24770
REPRO-2026-00086 published
RAGFlow MinerU parser Zip Slip allows arbitrary file overwrite and potential RCE via malicious ZIP archives.
CVE-2026-24770 critical Security
Variant found
pip (per GitHub advisory)
ragflow (RAGFlow)
8m 19s Feb 13, 2026
CVE-2025-64712
REPRO-2026-00084 published
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
CVE-2025-64712 critical Security
Variant found
pypi
unstructured
4m 50s Feb 13, 2026
CVE-2026-24009
REPRO-2026-00080 published
Docling-core YAML Deserialization RCE via FullLoader
CVE-2026-24009 high Security
Variant found
pip
docling-core
6m 1s Feb 13, 2026
CVE-2026-22807
REPRO-2026-00078 published
vLLM RCE via auto_map dynamic module loading
CVE-2026-22807 high Security pip
vllm
19m 50s Jan 22, 2026
CVE-2025-68145
REPRO-2026-00076 published
MCP Server Git: Path Traversal via Missing Repository Path Validation
CVE-2025-68145 critical Security pip
mcp-server-git
11m 29s Jan 21, 2026
CVE-2025-60021
REPRO-2026-00072 published
Apache bRPC: Remote Command Injection in Heap Profiler
CVE-2025-60021 critical Security cpp
brpc
47m 53s Jan 21, 2026
CVE-2026-23535
REPRO-2026-00070 published
wlc: Path traversal via unsanitized API slugs in download command
CVE-2026-23535 high Security pip
wlc
20m 59s Jan 17, 2026
CVE-2025-58367
REPRO-2026-00063 published
deepdiff: Class Pollution RCE via Delta Tuple Path Bypass
CVE-2025-58367 critical Security pip
deepdiff
1m 7s Jan 13, 2026
CVE-2025-64439
REPRO-2026-00062 published
langgraph-checkpoint: Constructor Deserialization RCE in JsonPlusSerializer
CVE-2025-64439 high Security pip
langgraph-checkpoint
1m 7s Jan 12, 2026
CVE-2025-61765
REPRO-2026-00061 published
python-socketio: Pickle Deserialization RCE in PubSub Manager
CVE-2025-61765 medium Security pip
python-socketio
1m 5s Jan 12, 2026
CVE-2025-68456
REPRO-2026-00054 published
Craft CMS: Unauthenticated Database Backup Trigger
CVE-2025-68456 critical Security composer
craftcms/cms
36m 45s Jan 8, 2026
CVE-2025-67303
REPRO-2026-00052 published
ComfyUI-Manager: Configuration File Exposure via Web-Accessible Path
CVE-2025-67303 high Security pip
ComfyUI-Manager
11m 32s Jan 8, 2026
CVE-2025-27520
REPRO-2026-00045 published
BentoML RCE via Insecure Deserialization
CVE-2025-27520 critical Security pip
bentoml
16m 37s Jan 7, 2026