The catalog
Browse CVE Reproductions
181 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00294 WordPress 7.0.1 pre-auth fresh-administrator chain to RCE REPRO-2026-00281 Apache Kafka SASL/OAUTHBEARER accepts unvalidated JWTs REPRO-2026-00293 Metabase arbitrary code execution via unsafe H2 connection property validation bypass REPRO-2026-00222 SimpleHelp OIDC authentication accepts unsigned/forged ID tokens, enabling remote authentication bypass and possible MFA bypass in versions 5.5.15 and earlier and 6.0 prereleases prior to the fixed release. REPRO-2026-00259 iCagenda unauthenticated file upload RCE in public event submission form REPRO-2026-00223 phpBB authentication bypass/account hijacking via OAuth login-link flow with arbitrary auth_provider=apache
181 reproductions
Clear filters Active CVE
REPRO-2026-00273 published
Vtiger CRM through 8.4.0 allows authenticated admin users to achieve remote code execution by uploading a crafted module ZIP that places PHP files in the web-accessible modules/ directory.
CVE-2026-23698 high Security
Variant found
other
Vtiger CRM
33m 54s Jul 8, 2026
REPRO-2026-00272 published
EGroupware contains an authorization bypass in SmallPartMediaRecorder::ajax_upload combined with arbitrary file write and file read primitives, enabling authenticated (or self-registered) attackers to overwrite header.inc.php and achieve remote code execution.
CVE-2026-27823 critical Security
Variant found
Composer
egroupware/egroupware
78m 4s Jul 8, 2026
REPRO-2026-00271 published
Apache Airflow <3.3.0 allows deserialization of attacker-controlled class paths in BaseSerialization.deserialize(), enabling DAG authors to trigger RCE in the Scheduler/API Server via malicious serialized DAGs.
CVE-2026-33264 critical Security
Variant found
PyPI
apache/airflow
34m 38s Jul 8, 2026
REPRO-2026-00270 published
9router before 0.4.44 allows unauthenticated remote OS command execution via the /api/tunnel/tailscale-install endpoint by injecting shell commands in the sudoPassword field when sudo does not prompt for a password.
CVE-2026-59800 critical Security
Variant found
npm
9router (npm)
45m 53s Jul 8, 2026
REPRO-2026-00269 published
SP Page Builder for Joomla allows unauthenticated arbitrary file upload via asset.uploadCustomIcon, enabling PHP upload and remote code execution.
CVE-2026-48908 critical Security
Variant found
Joomla extension
SP Page Builder (com_sppagebuilder)
77m 51s Jul 8, 2026
REPRO-2026-00268 published
Langflow’s /api/v1/responses endpoint contains an IDOR that lets any authenticated user execute another user’s flow by supplying the victim’s flow UUID.
CVE-2026-55255 critical Security
Variant found
pip
langflow (pip)
28m 29s Jul 8, 2026
REPRO-2026-00267 published
Apache Camel embedded HTTP/management servers can bypass authentication on subpaths when a non-root context path is configured, allowing unauthenticated access to protected routes and management endpoints.
CVE-2026-40022 high Security
Variant found
maven
org.apache.camel:camel-platform-http-main
20m 26s Jul 7, 2026
REPRO-2026-00266 published
Unauthenticated arbitrary file operations in Splunk Enterprise PostgreSQL sidecar service (SVD-2026-0603)
CVE-2026-20253 critical Security
Variant found
github
splunk/splunk
63m 18s Jul 7, 2026
REPRO-2026-00265 published
Linux kernel kTLS Use-After-Free
CVE-2024-26582 high Security
Variant found
github
torvalds/linux
49m 32s Jul 7, 2026
REPRO-2026-00264 published
Apache Camel camel-docling improperly validates custom CLI arguments, enabling argument injection and path traversal when untrusted data is mapped into docling invocation headers.
CVE-2026-40047 critical Security
Variant found
Maven
apache/camel
41m 23s Jul 7, 2026
REPRO-2026-00263 published
c-ares CVE-2026-33630 RCE primitive construction from confirmed remote UAF
CVE-2026-33630 high Security
Variant found
c
c-ares/c-ares
54m 27s Jul 7, 2026
REPRO-2026-00262 published
ColdFusion 2025 Lockdown: open-RDS unauth direct-Tomcat absolute-path FILEIO RCE confirmed
CVE-2026-48282 critical Security
Adobe ColdFusion
80m 25s Jul 7, 2026
REPRO-2026-00261 published
BerriAI LiteLLM SQL injection
CVE-2026-42271 high Security
Variant found
pip
BerriAI LiteLLM
168m 42s Jul 7, 2026
REPRO-2026-00259 published
iCagenda unauthenticated file upload RCE in public event submission form
CVE-2026-48939 critical Security
Variant found
joomla
iCagenda
107m 17s Jul 6, 2026
REPRO-2026-00258 published
Cudy LT300 3.0 OS command injection
CVE-2026-32833 high Security
Variant found
firmware
Cudy LT300 V3 firmware
93m 59s Jul 6, 2026
REPRO-2026-00257 published
Apache Airflow Google provider path traversal via GCS object names
CVE-2026-49297 high Security
Variant found
pip
apache-airflow-providers-google
56m 55s Jul 6, 2026
REPRO-2026-00256 published
Pagekit CMS privilege escalation leading to RCE
CVE-2026-57518 high Security
Variant found
github
pagekit/pagekit
23m 15s Jul 6, 2026
REPRO-2026-00255 published
JAIOTlink C492A-W6 Wi‑Fi IP camera firmware accepts default admin credentials (blank password) over HTTP Basic auth, enabling network‑adjacent attackers to access snapshots and privileged APIs.
CVE-2026-58453 critical Security
Variant found
firmware
jingwenyi/SmartCamera (Anyka N1
29m 42s Jul 6, 2026
REPRO-2026-00254 published
Vibe-Trading DNS rebinding authentication bypass leading to RCE
CVE-2026-58169 high Security
Variant found
Vibe-Trading (pip: vibe-trading-ai)
18m 8s Jul 6, 2026
REPRO-2026-00253 published
Pinpoint through 3.1.0 allows authenticated users to register internal webhook URLs, leading to SSRF when alarm webhooks are delivered.
CVE-2026-57947 medium Security
Variant found
maven
pinpoint-apm/pinpoint
59m 13s Jul 6, 2026