The catalog
Browse Reproductions
276 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
276 reproductions
REPRO-2026-00209 published
Oj Ruby gem stack buffer overflow via large :indent value
CVE-2026-54502 medium Security
Variant found
Ruby
oj
18m 33s Jul 2, 2026
REPRO-2026-00208 published
Oj Ruby gem uninitialized stack memory leak via long JSON keys
CVE-2026-54500 medium Security
Variant found
oj (Optimized JSON) Ruby gem
20m 41s Jul 2, 2026
REPRO-2026-00207 published
@fastify/middie encoded slash bypass on parameterized middleware paths
CVE-2026-14198 critical Security
Variant found
@fastify/middie
9m 46s Jul 2, 2026
REPRO-2026-00206 published
runc symlink deletion via malicious /dev symlink in container image
CVE-2026-41579 low Security
Variant found
github.com/opencontainers/runc
25m 21s Jul 2, 2026
REPRO-2026-00205 published
auth-fetch-mcp SSRF via IPv4-mapped IPv6 loopback bypass
CVE-2026-49857 high Security
Variant found
npm
ymw0407/auth-fetch-mcp
17m 11s Jul 2, 2026
REPRO-2026-00203 published
JetWidgets For Elementor Stored XSS via Animated Box animation_effect
CVE-2026-11380 medium Security
Variant found
jetmonsters/jetwidgets-for-elementor
29m 27s Jul 2, 2026
REPRO-2026-00202 published
Open VSX Registry serves HTML inline enabling session/token exfiltration
CVE-2026-4983 medium Security
Variant found
Eclipse Open VSX (openvsx server)
36m 21s Jul 2, 2026
REPRO-2026-00201 published
Unauthenticated RCE in Langflow via public flow build endpoint
CVE-2026-33017 critical Security
Variant found
pip
langflow
25m 8s Jul 2, 2026
REPRO-2026-00200 published
Jenkins CLI arbitrary file read via @ argument expansion
CVE-2024-23897 critical Security generic
jenkins
21m 31s Jul 2, 2026
REPRO-2026-00199 published
aiohttp static file directory traversal via follow_symlinks
CVE-2024-23334 high Security pip
aiohttp
11m 4s Jul 2, 2026
REPRO-2026-00198 published
Next.js middleware authorization bypass via x-middleware-subrequest
CVE-2025-29927 critical Security npm
next
37m 24s Jul 2, 2026
REPRO-2026-00197 published
TaskingAI web_reader plugin SSRF via /v1/execute
high Security github
taskingai
17m 35s Jul 2, 2026
REPRO-2026-00196 published
React Server Components Flight protocol remote code execution
CVE-2025-55182 critical Security npm
react-server-dom-webpack
34m 46s Jul 2, 2026
REPRO-2026-00195 published
Vite dev server access control can be bypassed using crafted query strings, allowing arbitrary file reads via the @fs handler when the dev server is exposed to the network.
CVE-2025-30208 medium Security npm
vite
23m 11s Jul 1, 2026
REPRO-2026-00194 published
Unauthenticated SQL injection in dotCMS Publish Audit API
CVE-2026-8054 critical Security
Variant found
github
dotCMS/core
116m 7s Jul 1, 2026
REPRO-2026-00193 published
ProFTPD ACL bypass via /proc/self/root path prefix in RNFR
CVE-2026-35025 high Security
Variant found
github
proftpd/proftpd
88m 18s Jul 1, 2026
REPRO-2026-00192 published
Gogs path traversal in organization name results in RCE through Git hooks
CVE-2026-52813 critical Security
Variant found
github
gogs/gogs
29m 54s Jul 1, 2026
REPRO-2026-00186 published
libssh2 via curl: malformed SSH packet length crashes SFTP client
CVE-2026-55200 critical Security c
libssh2
11m 23s Jun 25, 2026
REPRO-2026-00185 published
HashiCorp Nomad: path traversal in host volume plugin loader → client-host RCE
CVE-2026-7474 high Security
Variant found
go
nomad
48m 9s May 28, 2026
REPRO-2026-00184 published
Temporal Server: batcher worker cross-namespace authorization bypass (BatchActivityWithProtobuf)
CVE-2026-5199 low Security
Variant found
go
temporal
72m 49s May 28, 2026