The catalog
Browse CVE Reproductions
249 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
249 reproductions
Clear filters Active CVE
REPRO-2026-00357 published
Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical)
CVE-2026-94545 critical Security Known vulnerability npm
next
84m 10s Sep 23, 2026
REPRO-2026-00356 published
WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE
CVE-2026-87902 critical Security Known vulnerability github
WordPress/wordpress-develop
67m 36s Sep 22, 2026
REPRO-2026-00354 published
GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read
CVE-2026-85706 critical Security
Vulnerable-path variant
Known vulnerability
gitlab
138m 51s Sep 12, 2026
REPRO-2026-00352 published
Traefik digestAuth middleware gives empty secret to unknown usernames → auth bypass
CVE-2026-85595 high Security Known vulnerability github
traefik/traefik
65m 40s Sep 11, 2026
REPRO-2026-00351 published
Jenkins remember-me session fixation — attacker-plantable cookie value not rotated after login (SECURITY-4069)
CVE-2026-84652 high Security Known vulnerability github
jenkinsci/jenkins
26m 49s Sep 11, 2026
REPRO-2026-00350 published
Jenkins Stapler: CSRF crumb exposed in dynamically generated JavaScript endpoint (SECURITY-3607)
CVE-2026-84649 medium Security Known vulnerability github
jenkinsci/jenkins
51m 56s Sep 11, 2026
REPRO-2026-00349 published
Jenkins Stapler form binding instantiates arbitrary config types → RCE (SECURITY-3966)
CVE-2026-84647 high Security Known vulnerability github
jenkinsci/jenkins
51m 2s Sep 11, 2026
REPRO-2026-00348 published
curl: domain-scoped cookie for a public suffix (e.g. Domain=co.uk) leaks to sibling subdomains despite libpsl
CVE-2026-82209 low Security Known vulnerability
curl/libcurl
24m 28s Sep 11, 2026
REPRO-2026-00347 published
curl: Secure cookie attribute bypass when a TAB character precedes the Secure attribute in Set-Cookie
CVE-2026-80255 low Security Known vulnerability github
curl/curl
26m 16s Sep 11, 2026
REPRO-2026-00346 published
curl: native CA store flag not part of connection reuse matching, wrong trust store may authenticate reused TLS connections
CVE-2026-80231 low Security Known vulnerability github
curl/libcurl
40m 28s Sep 11, 2026
REPRO-2026-00345 published
Forgejo <16.0.4 RCE via crafted template repository (.forgejo/template expansion recreates .git folder adopted by git init)
CVE-2026-89094 critical Security Known vulnerability
forgejo
49m 42s Sep 11, 2026
REPRO-2026-00344 published
MikroTik RouterOS CVE-2026-67279 + CVE-2026-86060 unauthenticated privileged command-execution chain
CVE-2026-67279 high Security Known vulnerability
MikroTik RouterOS SSH
326m 3s Sep 7, 2026
REPRO-2026-00343 published
Jenkins XStream deserialization of nested PersistenceRoot objects leads to RCE via Stapler (SECURITY-3972)
CVE-2026-84645 high Security
Vulnerable-path variant
Known vulnerability github
jenkinsci/jenkins
44m 4s Sep 3, 2026
REPRO-2026-00342 published
Langflow contains an unauthenticated remote code execution vulnerability in the validate endpoint that can lead to arbitrary Python code execution as root.
CVE-2026-0768 critical Security Known vulnerability PyPI
langflow-ai/langflow
63m 8s Sep 2, 2026
REPRO-2026-00341 published
JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover
CVE-2026-82329 critical Security
Vulnerable-path variant
Known vulnerability
JFrog Artifactory
145m 14s Sep 1, 2026
REPRO-2026-00340 published
PaperCut NG/MF CVE-2026-81578 + CVE-2026-82078 unauthenticated RCE chain
CVE-2026-81578 critical Security Known vulnerability vendor
PaperCut NG/MF
163m 48s Aug 31, 2026
REPRO-2026-00337 published
Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640)
CVE-2026-18963 critical Security Known vulnerability
org.keycloak:keycloak-services (Maven)
54m 46s Aug 24, 2026
REPRO-2026-00336 published
NLTK <3.10.3 RCE in AllowlistUnpickler — validates pickle module string but not global name; dotted-name traversal escapes allowlist to reach arbitrary callables
CVE-2026-71513 high Security
Variant found
Known vulnerability github
nltk/nltk
23m 39s Aug 23, 2026
REPRO-2026-00335 published
MLflow unauthenticated full-read SSRF in webhook delivery via redirect-follow bypass of _validate_webhook_url guard
CVE-2026-64849 critical Security
Variant found
Known vulnerability PyPI
mlflow/mlflow
41m 3s Aug 23, 2026
REPRO-2026-00334 published
Authenticated command injection in pm2panel's /restart handler allows remote shell command execution on the host.
CVE-2026-72573 high Security
Variant found
Known vulnerability GitHub / Node.js web application
4xmen/pm2panel
14m 14s Aug 23, 2026