The catalog
Browse CVE Reproductions
249 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
249 reproductions
Clear filters Active CVE
REPRO-2026-00240 published
Langflow OSS SSRF and privilege escalation
CVE-2026-10129 high Security
Variant found
langflow/langflow
56m 49s Jul 6, 2026
REPRO-2026-00239 published
WP Review Slider Pro SQL injection
CVE-2026-8441 high Security
Variant found
https://wpreviewslider.com//WP Review Slider Pro
42m 0s Jul 6, 2026
REPRO-2026-00238 published
OpenBMB ChatDev unauthenticated path traversal file upload
CVE-2026-58166 critical Security
Variant found
github
OpenBMB/ChatDev
28m 27s Jul 6, 2026
REPRO-2026-00237 published
OpenZiti privilege escalation via overpermissive enrollment creation
CVE-2026-58165 high Security
Variant found
OpenZiti
22m 39s Jul 6, 2026
REPRO-2026-00236 published
Orkes Conductor unauthenticated RCE via inline script evaluators
CVE-2026-58138 critical Security
Variant found
conductor-oss/conductor (Orkes Conductor OSS)
24m 53s Jul 6, 2026
REPRO-2026-00235 published
PACSgear PACS Scan unauthenticated remote code execution
CVE-2026-58126 critical Security
Variant found
Hyland/PACSgear PACS Scan
64m 7s Jul 6, 2026
REPRO-2026-00234 published
Blocksy Companion Pro unauthenticated remote code execution
CVE-2026-57624 critical Security
Variant found
Creative Themes/Blocksy Companion Pro
37m 0s Jul 6, 2026
REPRO-2026-00233 published
Grav CMS unsafe deserialization and command injection RCE
CVE-2026-56700 critical Security
Variant found
getgrav/grav (Composer)
53m 20s Jul 6, 2026
REPRO-2026-00232 published
Page Builder CK unauthenticated arbitrary file upload to RCE
CVE-2026-56290 critical Security
Variant found
joomlack/page_builder_ck
23m 44s Jul 6, 2026
REPRO-2026-00231 published
HTTP/2 request smuggling in Vinyl Cache and Varnish Cache (VSV00019)
CVE-2026-50052 low Security
Variant found
github
varnish/varnish
28m 5s Jul 6, 2026
REPRO-2026-00230 published
Widget Options WordPress plugin contributor remote code execution
CVE-2026-54823 critical Security
Variant found
MarketingFire/Widget Options
28m 45s Jul 6, 2026
REPRO-2026-00229 published
CivetWeb PUT + SSI #exec RCE
CVE-VINEXT-CIVETWEB-PUT-SSI-RCE high Security
Variant found
github
civetweb/civetweb
34m 27s Jul 4, 2026
REPRO-2026-00223 published
phpBB authentication bypass/account hijacking via OAuth login-link flow with arbitrary auth_provider=apache
CVE-2026-48611 critical Security
Variant found
github
phpbb/phpbb
22m 9s Jul 4, 2026
REPRO-2026-00222 published
SimpleHelp OIDC authentication accepts unsigned/forged ID tokens, enabling remote authentication bypass and possible MFA bypass in versions 5.5.15 and earlier and 6.0 prereleases prior to the fixed release.
CVE-2026-48558 critical Security
Variant found
other (commercial, Java-based server application)
SimpleHelp
94m 25s Jul 4, 2026
REPRO-2026-00221 published
Linux kernel FUSE readdir cache out-of-bounds write
CVE-2026-31694 high Security
Variant found
Linux kernel (FUSE subsystem)
63m 5s Jul 3, 2026
REPRO-2026-00220 published
JuiceFS through 1.3.1 exposes debug/metrics endpoints via shared http.DefaultServeMux, enabling authentication bypass and leakage of sensitive metadata connection strings, with potential DoS via profiling handlers.
CVE-2026-59092 high Security
Variant found
go
JuiceFS (juicedata/juicefs)
14m 46s Jul 3, 2026
REPRO-2026-00219 published
AutoBangumi before 3.2.8 seeds a default admin account on empty databases, allowing unauthenticated users to log in with publicly known default credentials and gain full control.
CVE-2026-58466 critical Security
Variant found
standalone application (Python/FastAPI)
EstrellaXD/Auto_Bangumi
14m 56s Jul 3, 2026
REPRO-2026-00218 published
fast-mcp-telegram <=0.19.0 allows bearer token path traversal to authenticate as the default telegram.session, bypassing reserved session name protections and enabling unauthorized access to Telegram MCP tools.
CVE-2026-52830 critical Security
Variant found
pip
fast-mcp-telegram
17m 51s Jul 3, 2026
REPRO-2026-00217 published
9router hardcoded default fallback JWT secret allows authentication bypass
CVE-2026-49352 critical Security
Variant found
github
decolua/9router
13m 50s Jul 3, 2026
REPRO-2026-00212 published
DirtyClone Linux kernel page-cache corruption privilege escalation
CVE-2026-43503 high Security
Variant found
linux
Linux kernel
70m 55s Jul 3, 2026