Skip to content

The catalog

Browse Reproductions

244 verified reproductions

RSS Feed

244 reproductions

REPRO-2026-00343 published

Jenkins XStream deserialization of nested PersistenceRoot objects leads to RCE via Stapler (SECURITY-3972)

CVE-2026-84645 high Security Vulnerable-path variant Known vulnerability github
jenkinsci/jenkins
44m 4s Sep 3, 2026
REPRO-2026-00342 published

Langflow contains an unauthenticated remote code execution vulnerability in the validate endpoint that can lead to arbitrary Python code execution as root.

CVE-2026-0768 critical Security Known vulnerability PyPI
langflow-ai/langflow
63m 8s Sep 2, 2026
REPRO-2026-00341 published

JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover

CVE-2026-82329 critical Security Vulnerable-path variant Known vulnerability
JFrog Artifactory
145m 14s Sep 1, 2026
REPRO-2026-00340 published

PaperCut NG/MF CVE-2026-81578 + CVE-2026-82078 unauthenticated RCE chain

CVE-2026-81578 critical Security Known vulnerability vendor
PaperCut NG/MF
163m 48s Aug 31, 2026
REPRO-2026-00339 published

bubblewrap: sandbox escape via /oldroot symlink traversal during setup — files created on host

GHSA-PXHW-H44J-8PFX high Security Known vulnerability
bubblewrap
18m 28s Aug 26, 2026
REPRO-2026-00338 published

Apache Log4j2 serialized LogEvent filter bypass to conditional RCE

GHSA-LOG4J2-4255-MARSHALLEDOBJECT critical Security Known vulnerability maven
org.apache.logging.log4j:log4j-core
73m 31s Aug 26, 2026
REPRO-2026-00337 published

Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640)

CVE-2026-18963 critical Security Known vulnerability
org.keycloak:keycloak-services (Maven)
54m 46s Aug 24, 2026
REPRO-2026-00336 published

NLTK <3.10.3 RCE in AllowlistUnpickler — validates pickle module string but not global name; dotted-name traversal escapes allowlist to reach arbitrary callables

CVE-2026-71513 high Security Variant found Known vulnerability github
nltk/nltk
23m 39s Aug 23, 2026
REPRO-2026-00335 published

MLflow unauthenticated full-read SSRF in webhook delivery via redirect-follow bypass of _validate_webhook_url guard

CVE-2026-64849 critical Security Variant found Known vulnerability PyPI
mlflow/mlflow
41m 3s Aug 23, 2026
REPRO-2026-00334 published

Authenticated command injection in pm2panel's /restart handler allows remote shell command execution on the host.

CVE-2026-72573 high Security Variant found Known vulnerability GitHub / Node.js web application
4xmen/pm2panel
14m 14s Aug 23, 2026
REPRO-2026-00333 published

Crypt::OpenSSL::PKCS12 before 1.98 can crash with a NULL pointer dereference when `info_as_hash()` parses a crafted PKCS#12 containing a zero-length BMPSTRING attribute.

CVE-2026-17510 medium Security Variant found Known vulnerability CPAN
dsully/perl-crypt-openssl-pkcs12
17m 47s Aug 23, 2026
REPRO-2026-00332 published

Fledge backup upload shell command injection

CVE-2026-71284 high Security Variant found Known vulnerability github
fledge-iot/fledge
91m 3s Aug 23, 2026
REPRO-2026-00331 published

OpenCTI CVE-2026-39980 safeEjs destructuring fix bypass RCE

CVE-2026-39980 critical Security Variant found Known vulnerability github
opencti-platform/opencti
106m 24s Aug 23, 2026
REPRO-2026-00330 published

MariaDB 13.0.1-rc RCE chain: F-09 GRANT PROXY priv-esc (MDEV-40470) + /proc/self/maps ASLR leak + F-05 SYS_REFCURSOR heap UAF → JOP to system() as uid 999(mysql), pure SQL from a low-priv account

critical Security Variant found Known vulnerability github
mariadb/server
61m 33s Aug 23, 2026
REPRO-2026-00329 published

JetBrains TeamCity On-Premises unauthenticated RCE via agent polling protocol

CVE-2026-63077 critical Security Known vulnerability
JetBrains TeamCity
100m 55s Aug 23, 2026
REPRO-2026-00328 published

PasswordPusher allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership check that bypasses viewer-deletion restrictions.

CVE-2026-62382 medium Security Known vulnerability Ruby on Rails self-hosted application, also shipped as Docker image pglombardo/pwpush
pglombardo/PasswordPusher
21m 33s Aug 23, 2026
REPRO-2026-00327 published

Zimbra Collaboration unauthenticated RCE via Swatchdog/SNMP log-injection command injection (swatchrc dosnmp Perl backtick)

CVE-2026-73570 high Security Known vulnerability
Zimbra Collaboration (ZCS)
94m 1s Aug 23, 2026
REPRO-2026-00326 published

Hermes Agent Electron preview webview sandbox escape via CVE-2026-70608

CVE-2026-70608 high Security Dependency reachability github
hermes-agent
271m 8s Aug 23, 2026
REPRO-2026-00325 published

Wazuh cluster DAPI deserialization of untrusted data — RCE via sort_casting builtin resolution (getattr(builtins, 'exec')) in result merging

CVE-2026-44901 high Security Known vulnerability github
wazuh/wazuh
83m 25s Aug 23, 2026
REPRO-2026-00324 published

Unauthenticated path traversal in xmysql `/download` allows arbitrary file read via unsanitized `req.query.name`.

CVE-2026-72572 high Security Known vulnerability npm / JavaScript (Node.js, Express)
xmysql
12m 11s Aug 23, 2026