Skip to content

The catalog

Browse CVE Reproductions

249 verified reproductions

RSS Feed

249 reproductions

Clear filters
Active CVE
REPRO-2026-00380 published

Ghost CMS RCE via Bookmark Card Images (SVG handling in bundled image processing library)

CVE-2026-105642 high Security Known vulnerability github
TryGhost/Ghost
161m 52s Oct 6, 2026
REPRO-2026-00379 published

Environment/ini-file leaks — document-supplied URLs expand env and INI values and exfiltrate them to a remote server

CVE-2026-63270 medium Security Known vulnerability other
libreoffice/core
67m 3s Oct 6, 2026
REPRO-2026-00378 published

LFI and GET SSRF via GStreamer and HLS playlists — linked media makes GStreamer read local files and fetch remote URLs on open

CVE-2026-63269 medium Security Known vulnerability unknown
LibreOffice/core
119m 41s Oct 6, 2026
REPRO-2026-00377 published

LFI via calcext:data-mappings, sql provider and sdbc:flat file db href — document reads a local text file into the sheet

CVE-2026-63268 medium Security Known vulnerability Maven
LibreOffice/core
68m 53s Oct 6, 2026
REPRO-2026-00376 published

Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality — document-driven write to any user-writable path

CVE-2026-63266 high Security Known vulnerability other
LibreOffice/core
116m 55s Oct 6, 2026
REPRO-2026-00375 published

LFI and GET SSRF via calcext:data-mappings and csv provider — document open reads a local file into the sheet and issues an attacker-directed GET

CVE-2026-63267 medium Security Known vulnerability vendor
LibreOffice (The Document Foundation)
45m 32s Oct 5, 2026
REPRO-2026-00374 published

LibreOffice Calc RCE via calcext:data-mappings, sql provider and jdbc connector — document-named Java DB driver loaded from a remote class path URL on open

CVE-2026-63277 high Security Known vulnerability
LibreOffice Calc
144m 55s Oct 5, 2026
REPRO-2026-00373 published

Linux kernel iwlwifi PCIe UAF/double-free — iwl_pcie_rx_free() leaves freed RX pointers (rx_pool, global_table, rxq, alloc_page) non-NULL after free

CVE-2026-93796 medium Security Known vulnerability
linux kernel (torvalds/linux / stable linux.git)
55m 40s Sep 24, 2026
REPRO-2026-00372 published

CRI-O checkpoint restore bypasses destination Kubernetes security context

CVE-2026-92574 high Security Known vulnerability go
cri-o/cri-o
200m 9s Sep 24, 2026
REPRO-2026-00370 published

Erlang/OTP inets httpd parks request worker indefinitely on malformed chunk size sent after headers (unauthenticated remote DoS)

CVE-2026-69664 high Security Known vulnerability github
erlang/otp
323m 56s Sep 24, 2026
REPRO-2026-00369 published

Jenkins transient fields deserializable from config.xml → config object overwrite / RCE (SECURITY-3972 companion)

CVE-2026-84650 high Security Known vulnerability github
jenkinsci/jenkins
60m 48s Sep 24, 2026
REPRO-2026-00368 published

curl: wolfSSL CA-cache hit causes x509 store setup rerun that overrides user certificate verification callback

CVE-2026-82208 low Security Known vulnerability github
curl/curl
25m 40s Sep 24, 2026
REPRO-2026-00367 published

Jenkins stored XSS in system log viewer via agent log output (SECURITY-3476)

CVE-2026-84648 high Security Known vulnerability github
jenkinsci/jenkins
68m 48s Sep 24, 2026
REPRO-2026-00365 published

RouterOS SSH RSA key-identity mismatch permits authentication with a forged key sharing an authorized modulus

CVE-2026-67276 critical Security Known vulnerability
MikroTik RouterOS
34m 15s Sep 24, 2026
REPRO-2026-00363 published

h3 path traversal via unsanitized static file serving pathname

CVE-2026-86253 high Security Known vulnerability github
h3js/h3
21m 47s Sep 24, 2026
REPRO-2026-00362 published

PostgreSQL Anonymizer ≤3.1.3 arbitrary code execution as extension superuser via crafted masking constructs

CVE-2026-19633 high Security Known vulnerability
postgresql_anonymizer (PostgreSQL extension, Rust/pgrx since v2.0)
72m 52s Sep 24, 2026
REPRO-2026-00361 published

PostgreSQL fuzzystrmatch integer wraparound: levenshtein()/levenshtein_less_equal() overflow leads to OOB writes to effectively-arbitrary addresses (potential RCE)

CVE-2026-15742 high Security Known vulnerability github
postgres/postgres
507m 48s Sep 24, 2026
REPRO-2026-00360 published

Blind SQL injection in Zabbix API `CApiService.php` via the `sortfield` parameter allows low-privileged API users to exfiltrate database data and potentially compromise administrator accounts.

CVE-2026-23921 high Security Known vulnerability unknown
zabbix/zabbix
38m 26s Sep 24, 2026
REPRO-2026-00359 published

CVE-2026-84502: Ansible Automation Platform automation-controller — Project scm_url argument injection into git ls-remote --upload-pack yields RCE on controller task pod

CVE-2026-84502 critical Security Known vulnerability github
ansible/awx
68m 55s Sep 24, 2026
REPRO-2026-00358 published

Linux kernel af_unix GC race-condition UAF — unix_del_edge() frees dead SCC without unlinking scc_entry

CVE-2026-80521 high Security Known vulnerability
Linux kernel
78m 32s Sep 24, 2026