Skip to content

The catalog

Browse Reproductions

220 verified reproductions

RSS Feed

220 reproductions

REPRO-2026-00297 published

JFrog Artifactory privilege escalation allowing low-privileged users to obtain elevated permissions

high Security Known vulnerability product
Artifactory
122m 25s Jul 26, 2026
REPRO-2026-00296 published

Reported Horilla protected_media Referer authentication bypass

GHSA-9WJX-4J4R-FF8W high Security Variant found Known vulnerability github
horilla/horilla-hr
77m 9s Jul 26, 2026
REPRO-2026-00295 published

Horilla HRMS protected_media path traversal enables outside-root file read

GHSA-x52c-5hrq-76pq high Security Variant found Known vulnerability github
horilla/horilla-hr
87m 3s Jul 25, 2026
REPRO-2026-00294 published

WordPress 7.0.1 pre-auth fresh-administrator chain to RCE

CVE-2026-63030 critical Security Variant found Known vulnerability
WordPress Core
65m 17s Jul 19, 2026
REPRO-2026-00293 published

Metabase arbitrary code execution via unsafe H2 connection property validation bypass

CVE-2026-59826 critical Security Variant found Known vulnerability github
metabase/metabase
92m 57s Jul 17, 2026
REPRO-2026-00292 published

websocket-driver: message corruption via abuse of draft-WebSocket length headers

CVE-2026-54466 critical Security Variant found Known vulnerability npm
faye/websocket-driver-node
7m 28s Jul 16, 2026
REPRO-2026-00291 published

systeminformation networkInterfaces() Linux source-directive command injection

CVE-2026-50289 high Security Variant found Known vulnerability github
sebhildebrandt/systeminformation
14m 44s Jul 16, 2026
REPRO-2026-00290 published

ToolHive SSRF in remote MCP server authentication discovery

CVE-2026-58196 medium Security Variant found Known vulnerability github
github.com/stacklok/toolhive
43m 47s Jul 16, 2026
REPRO-2026-00289 published

Spinnaker Kustomize bake unsafe YAML tag processing leading to RCE

CVE-2026-55175 high Security Variant found Known vulnerability github
spinnaker/spinnaker
15m 51s Jul 15, 2026
REPRO-2026-00288 published

Horde VFS < 3.0.1 OS command injection via Horde_Vfs_Smb driver

CVE-2026-60102 high Security Variant found github
horde/vfs
12m 50s Jul 14, 2026
REPRO-2026-00287 published

Apache APISIX jwt-auth authentication bypass via algorithm confusion

CVE-2026-39999 critical Security Variant found github
apache/apisix
14m 33s Jul 14, 2026
REPRO-2026-00286 published

Log4j MapMessage emits invalid JSON for non-finite values

CVE-2026-49844 medium Security Variant found maven
org.apache.logging.log4j:log4j-api
11m 14s Jul 13, 2026
REPRO-2026-00285 published

Samba’s printing subsystem allows OS command injection via unescaped job description (%J), enabling remote code execution through crafted print jobs.

CVE-2026-4480 critical Security Variant found generic
samba-team/samba
28m 55s Jul 13, 2026
REPRO-2026-00284 published

XRING: Alibaba XQUIC QPACK ring-buffer resize underflow

high Security Variant found github
Alibaba XQUIC
20m 53s Jul 11, 2026
REPRO-2026-00283 published

Nuclio cron trigger shell command injection leading to RCE

CVE-2026-52831 critical Security Variant found go
github.com/nuclio/nuclio
89m 0s Jul 11, 2026
REPRO-2026-00282 published

Apache Tomcat partial PUT session deserialization RCE

CVE-2025-24813 critical Security maven
Apache Tomcat
42m 34s Jul 11, 2026
REPRO-2026-00281 published

Apache Kafka SASL/OAUTHBEARER accepts unvalidated JWTs

CVE-2026-33557 critical Security Variant found maven
Apache Kafka
44m 25s Jul 11, 2026
REPRO-2026-00280 published

Apache Tomcat examples app XSS in numguess.jsp

CVE-2026-50229 medium Security Variant found github
apache/tomcat
16m 6s Jul 9, 2026
REPRO-2026-00279 published

Apache OpenNLP SvmDoccatModel unsafe deserialization

CVE-2026-43825 high Security Variant found github
apache/opennlp
14m 59s Jul 9, 2026
REPRO-2026-00278 published

libcurl HTTP/2 stream-dependency tree use-after-free

CVE-2026-10536 critical Security Variant found github
curl/libcurl
22m 30s Jul 9, 2026