The catalog
Browse Reproductions
276 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
276 reproductions
REPRO-2026-00317 published
Rails Active Storage variant processing arbitrary file read and potential RCE
CVE-2026-66066 critical Security Known vulnerability github
rails/rails
148m 42s Aug 1, 2026
REPRO-2026-00316 published
marimo Pre-Auth RCE via Terminal WebSocket Authentication Bypass (/terminal/ws missing validate_auth)
CVE-2026-39987 critical Security Known vulnerability github
marimo
24m 19s Jul 30, 2026
REPRO-2026-00315 published
Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment
CVE-2026-59726 critical Security Known vulnerability npm
ruflo
34m 45s Jul 30, 2026
REPRO-2026-00314 published
OpenCTI authentication bypass via user impersonation
CVE-2026-27960 critical Security Known vulnerability docker
opencti
44m 34s Jul 30, 2026
REPRO-2026-00312 published
Gitea diffpatch Git hook installation leads to remote code execution
CVE-2026-60004 critical Security Known vulnerability github
go-gitea/gitea
30m 6s Jul 29, 2026
REPRO-2026-00311 published
xrdp Xvnc backend authentication issue on RHEL 9
CVE-2026-55626 high Security Known vulnerability github
neutrinolabs/xrdp
64m 30s Jul 29, 2026
REPRO-2026-00310 published
Flowise arbitrary file access via unvalidated chatflowId/chatId
CVE-2025-71334 critical Security Known vulnerability npm
FlowiseAI/Flowise
66m 57s Jul 28, 2026
REPRO-2026-00309 published
PipeWire sandbox escape via malicious library loading in PulseAudio compatibility layer
CVE-2026-5674 high Security Known vulnerability
pipewire (pipewire-pulse daemon)
88m 8s Jul 28, 2026
REPRO-2026-00308 published
NGINX ASLR-enabled network RCE
CVE-2026-42533 critical Security Known vulnerability github
nginx/nginx
71m 44s Jul 27, 2026
REPRO-2026-00307 published
vBulletin runtime template runMaths pre-auth RCE
CVE-2026-61511 critical Security Discovery hunt
vBulletin
139m 11s Jul 27, 2026
REPRO-2026-00306 published
fastjson2 AutoType type-resolution flaw may lead to remote code execution
critical Security Discovery hunt github
alibaba/fastjson2
108m 42s Jul 27, 2026
REPRO-2026-00305 published
SiYuan missing authorization in /mcp enables unauthenticated administrator takeover via Publish proxy
CVE-2026-66012 critical Security Known vulnerability github
siyuan
171m 57s Jul 27, 2026
REPRO-2026-00304 published
NoteGen chat preview XSS via unsanitized HTML rendering before 0.32.0
CVE-2026-17496 high Security Known vulnerability github
note-gen
78m 29s Jul 27, 2026
REPRO-2026-00303 published
AWS API MCP Server security policy bypass via startup initialization failure
CVE-2026-16584 high Security Known vulnerability pip
awslabs.aws-api-mcp-server
29m 52s Jul 27, 2026
REPRO-2026-00302 published
datamodel-code-generator code injection via customBasePath before 0.70.0
CVE-2026-63720 high Security Known vulnerability pip
datamodel-code-generator
13m 44s Jul 27, 2026
REPRO-2026-00300 published
OpenRemote console registration authentication bypass via known asset identifier
CVE-2026-66013 critical Security Known vulnerability github
openremote
35m 36s Jul 27, 2026
REPRO-2026-00299 published
Horilla protected_media public-prefix normalization bypass: unauthenticated private in-root read on the repaired release
high Security Known vulnerability github
horilla/horilla-hr
84m 5s Jul 27, 2026
REPRO-2026-00298 published
Horilla protected_media composed chain: unauthenticated outside-root file read, with necessity controls for each component defect
high Security Known vulnerability github
horilla/horilla-hr
54m 42s Jul 27, 2026
REPRO-2026-00297 published
JFrog Artifactory privilege escalation allowing low-privileged users to obtain elevated permissions
high Security Known vulnerability product
Artifactory
122m 25s Jul 26, 2026
REPRO-2026-00296 published
Reported Horilla protected_media Referer authentication bypass
GHSA-9WJX-4J4R-FF8W high Security
Variant found
Known vulnerability github
horilla/horilla-hr
77m 9s Jul 26, 2026