The catalog
Browse CVE Reproductions
249 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
249 reproductions
Clear filters Active CVE
REPRO-2026-00282 published
Apache Tomcat partial PUT session deserialization RCE
CVE-2025-24813 critical Security maven
Apache Tomcat
42m 34s Jul 11, 2026
REPRO-2026-00281 published
Apache Kafka SASL/OAUTHBEARER accepts unvalidated JWTs
CVE-2026-33557 critical Security
Variant found
maven
Apache Kafka
44m 25s Jul 11, 2026
REPRO-2026-00280 published
Apache Tomcat examples app XSS in numguess.jsp
CVE-2026-50229 medium Security
Variant found
github
apache/tomcat
16m 6s Jul 9, 2026
REPRO-2026-00279 published
Apache OpenNLP SvmDoccatModel unsafe deserialization
CVE-2026-43825 high Security
Variant found
github
apache/opennlp
14m 59s Jul 9, 2026
REPRO-2026-00278 published
libcurl HTTP/2 stream-dependency tree use-after-free
CVE-2026-10536 critical Security
Variant found
github
curl/libcurl
22m 30s Jul 9, 2026
REPRO-2026-00277 published
Apache Airflow DAG author RCE via unrestricted import_string() in BaseSerialization.deserialize()
CVE-2026-33264 critical Security
Variant found
github
apache/airflow
16m 12s Jul 9, 2026
REPRO-2026-00276 published
Apache Gravitino unauthenticated H2 JDBC URL injection via testConnection API
CVE-2026-41042 critical Security
Variant found
github
apache/gravitino
22m 47s Jul 9, 2026
REPRO-2026-00275 published
Coolify terminal WebSocket endpoints lack proper authorization checks, allowing low-privileged members to access terminal functionality and achieve remote command execution on managed hosts.
CVE-2026-34047 critical Security
Variant found
Composer
coollabsio/coolify
44m 2s Jul 8, 2026
REPRO-2026-00274 published
@better-auth/sso <1.6.11 allows non-blind SSRF via unvalidated OIDC endpoint URLs during SSO provider registration, with potential account takeover when trustEmailVerified is enabled.
CVE-2026-53513 critical Security
Variant found
npm
@better-auth/sso
30m 49s Jul 8, 2026
REPRO-2026-00273 published
Vtiger CRM through 8.4.0 allows authenticated admin users to achieve remote code execution by uploading a crafted module ZIP that places PHP files in the web-accessible modules/ directory.
CVE-2026-23698 high Security
Variant found
other
Vtiger CRM
33m 54s Jul 8, 2026
REPRO-2026-00272 published
EGroupware contains an authorization bypass in SmallPartMediaRecorder::ajax_upload combined with arbitrary file write and file read primitives, enabling authenticated (or self-registered) attackers to overwrite header.inc.php and achieve remote code execution.
CVE-2026-27823 critical Security
Variant found
Composer
egroupware/egroupware
78m 4s Jul 8, 2026
REPRO-2026-00270 published
9router before 0.4.44 allows unauthenticated remote OS command execution via the /api/tunnel/tailscale-install endpoint by injecting shell commands in the sudoPassword field when sudo does not prompt for a password.
CVE-2026-59800 critical Security
Variant found
npm
9router (npm)
45m 53s Jul 8, 2026
REPRO-2026-00269 published
SP Page Builder for Joomla allows unauthenticated arbitrary file upload via asset.uploadCustomIcon, enabling PHP upload and remote code execution.
CVE-2026-48908 critical Security
Variant found
Joomla extension
SP Page Builder (com_sppagebuilder)
77m 51s Jul 8, 2026
REPRO-2026-00268 published
Langflow’s /api/v1/responses endpoint contains an IDOR that lets any authenticated user execute another user’s flow by supplying the victim’s flow UUID.
CVE-2026-55255 critical Security
Variant found
pip
langflow (pip)
28m 29s Jul 8, 2026
REPRO-2026-00267 published
Apache Camel embedded HTTP/management servers can bypass authentication on subpaths when a non-root context path is configured, allowing unauthenticated access to protected routes and management endpoints.
CVE-2026-40022 high Security
Variant found
maven
org.apache.camel:camel-platform-http-main
20m 26s Jul 7, 2026
REPRO-2026-00266 published
Unauthenticated arbitrary file operations in Splunk Enterprise PostgreSQL sidecar service (SVD-2026-0603)
CVE-2026-20253 critical Security
Variant found
github
splunk/splunk
63m 18s Jul 7, 2026
REPRO-2026-00265 published
Linux kernel kTLS Use-After-Free
CVE-2024-26582 high Security
Variant found
github
torvalds/linux
49m 32s Jul 7, 2026
REPRO-2026-00264 published
Apache Camel camel-docling improperly validates custom CLI arguments, enabling argument injection and path traversal when untrusted data is mapped into docling invocation headers.
CVE-2026-40047 critical Security
Variant found
Maven
apache/camel
41m 23s Jul 7, 2026
REPRO-2026-00263 published
c-ares CVE-2026-33630 RCE primitive construction from confirmed remote UAF
CVE-2026-33630 high Security
Variant found
c
c-ares/c-ares
54m 27s Jul 7, 2026
REPRO-2026-00262 published
ColdFusion 2025 Lockdown: open-RDS unauth direct-Tomcat absolute-path FILEIO RCE confirmed
CVE-2026-48282 critical Security
Adobe ColdFusion
80m 25s Jul 7, 2026