The catalog
Browse Reproductions
276 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
276 reproductions
REPRO-2026-00337 published
Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640)
CVE-2026-18963 critical Security Known vulnerability
org.keycloak:keycloak-services (Maven)
54m 46s Aug 24, 2026
REPRO-2026-00336 published
NLTK <3.10.3 RCE in AllowlistUnpickler — validates pickle module string but not global name; dotted-name traversal escapes allowlist to reach arbitrary callables
CVE-2026-71513 high Security
Variant found
Known vulnerability github
nltk/nltk
23m 39s Aug 23, 2026
REPRO-2026-00335 published
MLflow unauthenticated full-read SSRF in webhook delivery via redirect-follow bypass of _validate_webhook_url guard
CVE-2026-64849 critical Security
Variant found
Known vulnerability PyPI
mlflow/mlflow
41m 3s Aug 23, 2026
REPRO-2026-00334 published
Authenticated command injection in pm2panel's /restart handler allows remote shell command execution on the host.
CVE-2026-72573 high Security
Variant found
Known vulnerability GitHub / Node.js web application
4xmen/pm2panel
14m 14s Aug 23, 2026
REPRO-2026-00333 published
Crypt::OpenSSL::PKCS12 before 1.98 can crash with a NULL pointer dereference when `info_as_hash()` parses a crafted PKCS#12 containing a zero-length BMPSTRING attribute.
CVE-2026-17510 medium Security
Variant found
Known vulnerability CPAN
dsully/perl-crypt-openssl-pkcs12
17m 47s Aug 23, 2026
REPRO-2026-00332 published
Fledge backup upload shell command injection
CVE-2026-71284 high Security
Variant found
Known vulnerability github
fledge-iot/fledge
91m 3s Aug 23, 2026
REPRO-2026-00331 published
OpenCTI CVE-2026-39980 safeEjs destructuring fix bypass RCE
CVE-2026-39980 critical Security
Variant found
Known vulnerability github
opencti-platform/opencti
106m 24s Aug 23, 2026
REPRO-2026-00330 published
MariaDB 13.0.1-rc RCE chain: F-09 GRANT PROXY priv-esc (MDEV-40470) + /proc/self/maps ASLR leak + F-05 SYS_REFCURSOR heap UAF → JOP to system() as uid 999(mysql), pure SQL from a low-priv account
critical Security
Variant found
Known vulnerability github
mariadb/server
61m 33s Aug 23, 2026
REPRO-2026-00329 published
JetBrains TeamCity On-Premises unauthenticated RCE via agent polling protocol
CVE-2026-63077 critical Security Known vulnerability
JetBrains TeamCity
100m 55s Aug 23, 2026
REPRO-2026-00328 published
PasswordPusher allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership check that bypasses viewer-deletion restrictions.
CVE-2026-62382 medium Security Known vulnerability Ruby on Rails self-hosted application, also shipped as Docker image pglombardo/pwpush
pglombardo/PasswordPusher
21m 33s Aug 23, 2026
REPRO-2026-00327 published
Zimbra Collaboration unauthenticated RCE via Swatchdog/SNMP log-injection command injection (swatchrc dosnmp Perl backtick)
CVE-2026-73570 high Security Known vulnerability
Zimbra Collaboration (ZCS)
94m 1s Aug 23, 2026
REPRO-2026-00326 published
Hermes Agent Electron preview webview sandbox escape via CVE-2026-70608
CVE-2026-70608 high Security Dependency reachability github
hermes-agent
271m 8s Aug 23, 2026
REPRO-2026-00325 published
Wazuh cluster DAPI deserialization of untrusted data — RCE via sort_casting builtin resolution (getattr(builtins, 'exec')) in result merging
CVE-2026-44901 high Security Known vulnerability github
wazuh/wazuh
83m 25s Aug 23, 2026
REPRO-2026-00324 published
Unauthenticated path traversal in xmysql `/download` allows arbitrary file read via unsanitized `req.query.name`.
CVE-2026-72572 high Security Known vulnerability npm / JavaScript (Node.js, Express)
xmysql
12m 11s Aug 23, 2026
REPRO-2026-00323 published
Google::Auth for Perl command injection: external_account credentials JSON executable run via ungated system() → RCE
CVE-2026-66902 critical Security Known vulnerability
Google-Auth
16m 52s Aug 23, 2026
REPRO-2026-00322 published
Jenkins Remoting JEP-200 deserialization filter bypass (SECURITY-3911): unfiltered ClassNotFoundException fallback in MultiClassLoaderSerializer.resolveClass and ObjectInputStreamEx.resolveClass lets agents deserialize blocked core-classpath classes on the controller
CVE-2026-70426 critical Security Known vulnerability
jenkinsci/remoting (hudson.remoting)
162m 43s Aug 23, 2026
REPRO-2026-00321 published
huggingface/transformers <5.10.0: path traversal via chat_template dict keys in save_pretrained() → arbitrary file write → RCE (cron.d drop)
CVE-2026-9856 high Security Known vulnerability
huggingface/transformers
0m 19s Aug 23, 2026
REPRO-2026-00320 published
CodeIgniter4 is_image/mime_in upload validation bypass — unrestricted file upload leading to RCE
CVE-2026-63223 critical Security Known vulnerability github
codeigniter4/framework
24m 2s Aug 23, 2026
REPRO-2026-00319 published
MariaDB Galera SST remote_auth shell command injection (wsrep_shell_char blacklist bypass) — candidate for v12sec 2026-07-31 0day
critical Security Known vulnerability github
MariaDB/server
84m 16s Aug 1, 2026
REPRO-2026-00318 published
mcp-toolbox authorization bypass: unauthenticated tool invocation via direct HTTP API
CVE-2026-14537 high Security Known vulnerability github
googleapis/genai-toolbox
37m 46s Aug 1, 2026