The catalog
Browse CVE Reproductions
249 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
249 reproductions
Clear filters Active CVE
REPRO-2026-00261 published
BerriAI LiteLLM SQL injection
CVE-2026-42271 high Security
Variant found
pip
BerriAI LiteLLM
168m 42s Jul 7, 2026
REPRO-2026-00259 published
iCagenda unauthenticated file upload RCE in public event submission form
CVE-2026-48939 critical Security
Variant found
joomla
iCagenda
107m 17s Jul 6, 2026
REPRO-2026-00258 published
Cudy LT300 3.0 OS command injection
CVE-2026-32833 high Security
Variant found
firmware
Cudy LT300 V3 firmware
93m 59s Jul 6, 2026
REPRO-2026-00257 published
Apache Airflow Google provider path traversal via GCS object names
CVE-2026-49297 high Security
Variant found
pip
apache-airflow-providers-google
56m 55s Jul 6, 2026
REPRO-2026-00256 published
Pagekit CMS privilege escalation leading to RCE
CVE-2026-57518 high Security
Variant found
github
pagekit/pagekit
23m 15s Jul 6, 2026
REPRO-2026-00255 published
JAIOTlink C492A-W6 Wi‑Fi IP camera firmware accepts default admin credentials (blank password) over HTTP Basic auth, enabling network‑adjacent attackers to access snapshots and privileged APIs.
CVE-2026-58453 critical Security
Variant found
firmware
jingwenyi/SmartCamera (Anyka N1
29m 42s Jul 6, 2026
REPRO-2026-00254 published
Vibe-Trading DNS rebinding authentication bypass leading to RCE
CVE-2026-58169 high Security
Variant found
Vibe-Trading (pip: vibe-trading-ai)
18m 8s Jul 6, 2026
REPRO-2026-00253 published
Pinpoint through 3.1.0 allows authenticated users to register internal webhook URLs, leading to SSRF when alarm webhooks are delivered.
CVE-2026-57947 medium Security
Variant found
maven
pinpoint-apm/pinpoint
59m 13s Jul 6, 2026
REPRO-2026-00252 published
Divi Form Builder WordPress plugin allows unauthenticated arbitrary file upload via user-controlled acceptFileTypes, leading to RCE by uploading executable PHP extensions and accessing them in /wp-content/uploads/de_fb_uploads/.
CVE-2026-5524 critical Security wordpress
divi-form-builder
20m 35s Jul 6, 2026
REPRO-2026-00251 published
Premmerce Wishlist for WooCommerce unauthenticated SQL injection
CVE-2026-54849 critical Security
Variant found
Premmerce/Premmerce Wishlist for WooCommerce
27m 26s Jul 6, 2026
REPRO-2026-00250 published
JeecgBoot broken access control privilege escalation
CVE-2026-58377 high Security
Variant found
github
jeecgboot/JeecgBoot
31m 46s Jul 6, 2026
REPRO-2026-00249 published
ZAP ViewState add-on insecure deserialization RCE
CVE-2026-57527 high Security
Variant found
github
zaproxy/zap-extensions
26m 16s Jul 6, 2026
REPRO-2026-00248 published
containerd CRI checkpoint import RCE
CVE-2026-50195 critical Security
Variant found
github.com/containerd/containerd/v2
39m 23s Jul 6, 2026
REPRO-2026-00247 published
Kestra unauthenticated RCE via AuthenticationFilter path bypass
CVE-2026-49869 critical Security
Variant found
io.kestra:kestra (Kestra OSS)
26m 25s Jul 6, 2026
REPRO-2026-00246 published
Gradio FileExplorer path traversal
CVE-2026-49119 high Security
Variant found
github
gradio-app/gradio
21m 20s Jul 6, 2026
REPRO-2026-00245 published
Coolify authenticated command injection in Destination Network Management
CVE-2026-34594 high Security
Variant found
coollabsio/coolify
50m 51s Jul 6, 2026
REPRO-2026-00244 published
Feast Feature Server unauthenticated arbitrary file write to RCE
CVE-2026-23537 critical Security
Variant found
github
feast-dev/feast
37m 2s Jul 6, 2026
REPRO-2026-00243 published
Keycloak JWT algorithm confusion privilege escalation
CVE-2026-11800 high Security
Variant found
github
keycloak/keycloak
46m 0s Jul 6, 2026
REPRO-2026-00242 published
SMS Alert WordPress plugin <= 3.9.5 allows unauthenticated attackers to change a user’s email and reset their password, leading to account takeover and privilege escalation when OTP password reset verification is enabled.
CVE-2026-11387 critical Security
Variant found
WordPress plugin (hosted on WordPress.org SVN, not GitHub)
sms-alert
22m 56s Jul 6, 2026
REPRO-2026-00241 published
SALESmanago & Leadoo WordPress plugin SQL injection
CVE-2026-10835 high Security
Variant found
Unknown/SALESmanago & Leadoo
50m 2s Jul 6, 2026