The catalog
Browse CVE Reproductions
197 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00294 WordPress 7.0.1 pre-auth fresh-administrator chain to RCE REPRO-2026-00297 JFrog Artifactory privilege escalation allowing low-privileged users to obtain elevated permissions REPRO-2026-00306 fastjson2 AutoType type-resolution flaw may lead to remote code execution REPRO-2026-00319 MariaDB Galera SST remote_auth shell command injection (wsrep_shell_char blacklist bypass) — candidate for v12sec 2026-07-31 0day REPRO-2026-00308 NGINX ASLR-enabled network RCE REPRO-2026-00307 vBulletin runtime template runMaths pre-auth RCE
197 reproductions
Clear filters Active CVE
REPRO-2026-00198 published
Next.js middleware authorization bypass via x-middleware-subrequest
CVE-2025-29927 critical Security npm
next
37m 24s Jul 2, 2026
REPRO-2026-00196 published
React Server Components Flight protocol remote code execution
CVE-2025-55182 critical Security npm
react-server-dom-webpack
34m 46s Jul 2, 2026
REPRO-2026-00195 published
Vite dev server access control can be bypassed using crafted query strings, allowing arbitrary file reads via the @fs handler when the dev server is exposed to the network.
CVE-2025-30208 medium Security npm
vite
23m 11s Jul 1, 2026
REPRO-2026-00194 published
Unauthenticated SQL injection in dotCMS Publish Audit API
CVE-2026-8054 critical Security
Variant found
github
dotCMS/core
116m 7s Jul 1, 2026
REPRO-2026-00193 published
ProFTPD ACL bypass via /proc/self/root path prefix in RNFR
CVE-2026-35025 high Security
Variant found
github
proftpd/proftpd
88m 18s Jul 1, 2026
REPRO-2026-00192 published
Gogs path traversal in organization name results in RCE through Git hooks
CVE-2026-52813 critical Security
Variant found
github
gogs/gogs
29m 54s Jul 1, 2026
REPRO-2026-00186 published
libssh2 via curl: malformed SSH packet length crashes SFTP client
CVE-2026-55200 critical Security c
libssh2
11m 23s Jun 25, 2026
REPRO-2026-00185 published
HashiCorp Nomad: path traversal in host volume plugin loader → client-host RCE
CVE-2026-7474 high Security
Variant found
go
nomad
48m 9s May 28, 2026
REPRO-2026-00184 published
Temporal Server: batcher worker cross-namespace authorization bypass (BatchActivityWithProtobuf)
CVE-2026-5199 low Security
Variant found
go
temporal
72m 49s May 28, 2026
REPRO-2026-00183 published
MapServer: heap-buffer-overflow in SLD Categorize parser (msSLDParseRasterSymbolizer)
CVE-2026-33721 medium Security
Variant found
c
mapserver
14m 33s May 28, 2026
REPRO-2026-00173 published
wolfSSL: ECCSI universal signature forgery via missing scalar range check
CVE-2026-5466 high Security
Variant found
source
wolfssl
16m 28s May 28, 2026
REPRO-2026-00172 published
wolfSSL: EVP ChaCha20-Poly1305 decryption returns plaintext without verifying authentication tag
CVE-2026-5479 high Security
Variant found
source
wolfssl
12m 46s May 28, 2026
REPRO-2026-00171 published
nginx WebDAV: heap-buffer-overflow in COPY/MOVE with alias directive
CVE-2026-27654 high Security
Variant found
source
nginx
21m 40s May 28, 2026
REPRO-2026-00170 published
jq: integer overflow in jv_string_concat triggers heap buffer overflow on large strings
CVE-2026-32316 high Security
Variant found
github
jq
32m 33s May 28, 2026
REPRO-2026-00169 published
DataEase: stacked-query SQL injection via previewSql with allowMultiQueries
CVE-2026-40900 high Security
Variant found
github
dataease
58m 29s May 26, 2026
REPRO-2026-00168 published
DataEase: authentication bypass via password-derived HMAC JWT signing key
CVE-2026-23958 critical Security
Variant found
github
dataease
100m 11s May 25, 2026
REPRO-2026-00167 published
DataEase: Quartz JobStore Java deserialization RCE via QRTZ_JOB_DETAILS
CVE-2026-40901 high Security github
dataease
179m 9s May 25, 2026
REPRO-2026-00165 published
DataEase: JDBC parameter blocklist bypass via Lombok @Data setter exposure
CVE-2026-40899 medium Security
Variant found
github
dataease
111m 23s May 25, 2026
REPRO-2026-00160 published
Arelle: unauthenticated RCE via /rest/configure plugins URL parameter
CVE-2026-42796 critical Security
Variant found
pip
arelle
48m 18s May 23, 2026
REPRO-2026-00159 published
libheif: heap-buffer-overflow write decoding 1x4 grid of odd-height tiles
CVE-2026-32740 high Security
Variant found
c
libheif
41m 53s May 23, 2026