The catalog
Browse Reproductions
220 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00294 WordPress 7.0.1 pre-auth fresh-administrator chain to RCE REPRO-2026-00297 JFrog Artifactory privilege escalation allowing low-privileged users to obtain elevated permissions REPRO-2026-00306 fastjson2 AutoType type-resolution flaw may lead to remote code execution REPRO-2026-00319 MariaDB Galera SST remote_auth shell command injection (wsrep_shell_char blacklist bypass) — candidate for v12sec 2026-07-31 0day REPRO-2026-00308 NGINX ASLR-enabled network RCE REPRO-2026-00307 vBulletin runtime template runMaths pre-auth RCE
220 reproductions
REPRO-2026-00131 published
Apache Tomcat EncryptInterceptor Bypass via CVE-2026-29146 Fix Error - Missing Encryption of Sensitive Data
CVE-2026-34486 high Security
Variant found
Apache Tomcat
19m 38s Apr 14, 2026
REPRO-2026-00130 published
pymetasploit3 command injection
CVE-2026-5463 high Security
Variant found
PyPI
DanMcInerney/pymetasploit3
36m 8s Apr 4, 2026
REPRO-2026-00129 published
Go MCP SDK DNS Rebinding - Server-Side Request Forgery on AI Infrastructure
CVE-2026-34742 high Security
Variant found
Go module
github.com/modelcontextprotocol/go-sdk
38m 55s Apr 4, 2026
REPRO-2026-00128 published
Haraka Mail Server DoS via __proto__ prototype pollution in email headers
CVE-2026-34752 high Security
Variant found
github
npm/Haraka
17m 5s Apr 4, 2026
REPRO-2026-00127 published
cpp-httplib HTTP Request Smuggling via Unconsumed GET Request Body
CVE-2026-34441 medium Security
Variant found
github
yhirose/cpp-httplib
61m 29s Apr 4, 2026
REPRO-2026-00126 published
Cesanta Mongoose mDNS Stack Buffer Overflow - Remote Code Execution PoC
CVE-2026-5245 medium Security
Variant found
github
cesanta/mongoose
53m 53s Apr 2, 2026
REPRO-2026-00125 published
Grafana SQL Expressions RCE
CVE-2026-27876 critical Security
Variant found
github
grafana/grafana
59m 16s Apr 1, 2026
REPRO-2026-00124 published
Vim modeline handling for the tabpanel option allows sandbox escape via autocmd_add, enabling OS command execution when opening a crafted file.
CVE-2026-34714 critical Security
Variant found
github
Vim
19m 38s Apr 1, 2026
REPRO-2026-00119 published
PyTorch: weights_only Unpickler RCE via SETITEM Type Confusion
CVE-2026-24747 high Security
Variant found
pip
torch
48m 8s Mar 2, 2026
REPRO-2026-00118 published
cve-2026-21518
CVE-2026-21518 high Security
40m 34s Feb 21, 2026
REPRO-2026-00115 published
eBay MCP Server Environment Variable Injection via Crafted Prompts
CVE-2026-27203 high Security npm
@anthropic-ai/ebay-mcp-server
11m 39s Feb 20, 2026
REPRO-2026-00114 published
D-Tale Remote Code Execution via Custom Filter Input
CVE-2026-27194 critical Security pip
dtale
11m 53s Feb 20, 2026
REPRO-2026-00113 published
Feathers OAuth Authorization Header Leak to Third-Party
CVE-2026-27192 high Security npm
@feathersjs/authentication-oauth
7m 45s Feb 20, 2026
REPRO-2026-00112 published
Statamic CMS Stored XSS via Markdown Fieldtype
CVE-2026-27197 critical Security composer
statamic/cms
7m 48s Feb 20, 2026
REPRO-2026-00111 published
Formwork CMS Improper Privilege Management in User Creation
CVE-2026-27198 high Security composer
getformwork/formwork
12m 42s Feb 20, 2026
REPRO-2026-00110 published
Deno Command Injection via Incomplete Metacharacter Blocklist
CVE-2026-27190 high Security rust
deno
10m 5s Feb 20, 2026
REPRO-2026-00109 published
Feathers OAuth Open Redirect Account Takeover
CVE-2026-27191 medium Security npm
@feathersjs/authentication-oauth
12m 54s Feb 20, 2026
REPRO-2026-00108 published
Zumba JSON Serializer PHP Object Injection
CVE-2026-27206 high Security composer
zumba/json-serializer
11m 26s Feb 20, 2026
REPRO-2026-00107 published
Swiper Prototype Pollution
CVE-2026-27212 high Security npm
swiper
10m 21s Feb 20, 2026
REPRO-2026-00106 published
Dagu Unauthenticated RCE via Inline DAG Spec
GHSA-6qr9-g2xw-cw92 critical Security go
github.com/dagu-org/dagu
18m 38s Feb 20, 2026