The catalog
Browse CVE Reproductions
249 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
249 reproductions
Clear filters Active CVE
REPRO-2026-00380 published
Ghost CMS RCE via Bookmark Card Images (SVG handling in bundled image processing library)
CVE-2026-105642 high Security Known vulnerability github
TryGhost/Ghost
161m 52s Oct 6, 2026
REPRO-2026-00379 published
Environment/ini-file leaks — document-supplied URLs expand env and INI values and exfiltrate them to a remote server
CVE-2026-63270 medium Security Known vulnerability other
libreoffice/core
67m 3s Oct 6, 2026
REPRO-2026-00378 published
LFI and GET SSRF via GStreamer and HLS playlists — linked media makes GStreamer read local files and fetch remote URLs on open
CVE-2026-63269 medium Security Known vulnerability unknown
LibreOffice/core
119m 41s Oct 6, 2026
REPRO-2026-00377 published
LFI via calcext:data-mappings, sql provider and sdbc:flat file db href — document reads a local text file into the sheet
CVE-2026-63268 medium Security Known vulnerability Maven
LibreOffice/core
68m 53s Oct 6, 2026
REPRO-2026-00376 published
Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality — document-driven write to any user-writable path
CVE-2026-63266 high Security Known vulnerability other
LibreOffice/core
116m 55s Oct 6, 2026
REPRO-2026-00375 published
LFI and GET SSRF via calcext:data-mappings and csv provider — document open reads a local file into the sheet and issues an attacker-directed GET
CVE-2026-63267 medium Security Known vulnerability vendor
LibreOffice (The Document Foundation)
45m 32s Oct 5, 2026
REPRO-2026-00374 published
LibreOffice Calc RCE via calcext:data-mappings, sql provider and jdbc connector — document-named Java DB driver loaded from a remote class path URL on open
CVE-2026-63277 high Security Known vulnerability
LibreOffice Calc
144m 55s Oct 5, 2026
REPRO-2026-00373 published
Linux kernel iwlwifi PCIe UAF/double-free — iwl_pcie_rx_free() leaves freed RX pointers (rx_pool, global_table, rxq, alloc_page) non-NULL after free
CVE-2026-93796 medium Security Known vulnerability
linux kernel (torvalds/linux / stable linux.git)
55m 40s Sep 24, 2026
REPRO-2026-00372 published
CRI-O checkpoint restore bypasses destination Kubernetes security context
CVE-2026-92574 high Security Known vulnerability go
cri-o/cri-o
200m 9s Sep 24, 2026
REPRO-2026-00370 published
Erlang/OTP inets httpd parks request worker indefinitely on malformed chunk size sent after headers (unauthenticated remote DoS)
CVE-2026-69664 high Security Known vulnerability github
erlang/otp
323m 56s Sep 24, 2026
REPRO-2026-00369 published
Jenkins transient fields deserializable from config.xml → config object overwrite / RCE (SECURITY-3972 companion)
CVE-2026-84650 high Security Known vulnerability github
jenkinsci/jenkins
60m 48s Sep 24, 2026
REPRO-2026-00368 published
curl: wolfSSL CA-cache hit causes x509 store setup rerun that overrides user certificate verification callback
CVE-2026-82208 low Security Known vulnerability github
curl/curl
25m 40s Sep 24, 2026
REPRO-2026-00367 published
Jenkins stored XSS in system log viewer via agent log output (SECURITY-3476)
CVE-2026-84648 high Security Known vulnerability github
jenkinsci/jenkins
68m 48s Sep 24, 2026
REPRO-2026-00365 published
RouterOS SSH RSA key-identity mismatch permits authentication with a forged key sharing an authorized modulus
CVE-2026-67276 critical Security Known vulnerability
MikroTik RouterOS
34m 15s Sep 24, 2026
REPRO-2026-00363 published
h3 path traversal via unsanitized static file serving pathname
CVE-2026-86253 high Security Known vulnerability github
h3js/h3
21m 47s Sep 24, 2026
REPRO-2026-00362 published
PostgreSQL Anonymizer ≤3.1.3 arbitrary code execution as extension superuser via crafted masking constructs
CVE-2026-19633 high Security Known vulnerability
postgresql_anonymizer (PostgreSQL extension, Rust/pgrx since v2.0)
72m 52s Sep 24, 2026
REPRO-2026-00361 published
PostgreSQL fuzzystrmatch integer wraparound: levenshtein()/levenshtein_less_equal() overflow leads to OOB writes to effectively-arbitrary addresses (potential RCE)
CVE-2026-15742 high Security Known vulnerability github
postgres/postgres
507m 48s Sep 24, 2026
REPRO-2026-00360 published
Blind SQL injection in Zabbix API `CApiService.php` via the `sortfield` parameter allows low-privileged API users to exfiltrate database data and potentially compromise administrator accounts.
CVE-2026-23921 high Security Known vulnerability unknown
zabbix/zabbix
38m 26s Sep 24, 2026
REPRO-2026-00359 published
CVE-2026-84502: Ansible Automation Platform automation-controller — Project scm_url argument injection into git ls-remote --upload-pack yields RCE on controller task pod
CVE-2026-84502 critical Security Known vulnerability github
ansible/awx
68m 55s Sep 24, 2026
REPRO-2026-00358 published
Linux kernel af_unix GC race-condition UAF — unix_del_edge() frees dead SCC without unlinking scc_entry
CVE-2026-80521 high Security Known vulnerability
Linux kernel
78m 32s Sep 24, 2026