All CVE Labs
Every real, disclosed CVE reproduced as a local lab on this site, newest first.
CVE-2026-68771: ComfyUI Unauthenticated RCE via Pickle Deserialization
An unauthenticated upload endpoint and a node that deserializes whatever lands in a folder combine into remote code execution with no login at all.
CVE-2026-65008: Grav CMS Authenticated RCE via Blueprint Callable Injection
What it actually takes to adapt a published PoC when it was written against an admin interface your target doesn't run.
CVE-2026-63720: datamodel-code-generator customBasePath Code Injection RCE
A code generator trusts a schema field enough to paste it, unescaped, into the Python module it writes — and that module runs on import.
CVE-2026-63030: WordPress Core Pre-Auth Admin Takeover ("wp2shell")
Two chained bugs in WordPress core, no plugin involved, combine into unauthenticated administrator account creation — actively exploited right now.
CVE-2026-62183: Apache Syncope Privilege Escalation
A self-service API endpoint in Apache Syncope lets any authenticated user grant themselves admin-level roles.
CVE-2026-60137: WordPress Core author__not_in SQL Injection
WP_Query only integer-casts author__not_in when it arrives as an array — send it as a bare string instead, and whatever follows your closing parenthesis runs as SQL.
CVE-2026-53595: FreeScout Account Takeover
A MySQL trailing-space quirk in a hash comparison is enough to let an attacker take over any FreeScout account, no authentication required.
CVE-2026-53591: FreeScout Unauthenticated Conversation Injection
A hash-comparison branch meant only for backward compatibility skips FreeScout's own signature check entirely, letting a guessed thread id and an invalid hash forge a reply into any conversation.
CVE-2026-53264: Linux Kernel net/sched Use-After-Free
A disposable-VM lab for a real, AI-assisted Linux kernel 0-day — how a use-after-free race in net/sched's traffic-control actions turns an unprivileged shell into root.
CVE-2026-48812: FreeScout Unauthenticated Attachment Disclosure
A one-line access check that only ever rejects two of three possible token states leaves years of historical attachments on any long-running FreeScout install downloadable by anyone who knows or guesses the URL.
CVE-2026-45295: FreeScout Open-Tracking Enumeration Oracle
Three HTTP status codes from an unauthenticated tracking-pixel endpoint are enough to enumerate a helpdesk's private conversations and silently corrupt their read-tracking data.
CVE-2026-38165: XDocReport Velocity Template Engine SSTI to RCE
A .docx template gets evaluated as trusted Apache Velocity code with zero sandboxing — reflection reaches Runtime.exec() and the server runs it as root.
CVE-2026-34197: Apache ActiveMQ Jolokia RCE
A JMX management bridge in Apache ActiveMQ turns a single authenticated API call into arbitrary code execution — actively exploited in the wild.
CVE-2026-20253: Splunk Enterprise Unauthenticated File Write Endpoint
A pre-auth endpoint on Splunk's PostgreSQL Sidecar Service returns the exact signature a public detection tool checks for — CVSS 9.8, and real, verifiable signal even without triggering the underlying file write.
CVE-2026-19478: GitLab GraphQL Fallback-Field Arbitrary Method Invocation
An unrecognized GraphQL field name paired with a future-version directive lets an unauthenticated request call any public method on GitLab's own ActiveRecord models.
CVE-2026-15964: Single Sign On For TNG Account Takeover
A password-reset nonce computed identically for every anonymous visitor, then printed straight into the page — turning a public value into full, unauthenticated admin account takeover.
CVE-2026-11349: WordPress Plugin Unauthenticated SQL Injection
Unauthenticated blind SQL injection in the Modern Events Calendar Lite WordPress plugin, with real data actually extracted, not just a proof-of-concept flag.
CVE-2026-6675: Responsive Blocks Unauthenticated Open Email Relay
A REST route registered with permission_callback => '__return_true' hands wp_mail() an attacker-chosen recipient, subject, and body — turning any site running the plugin into a free spam relay.
CVE-2026-5813: PHPGurukul Course Registration SQL Injection
A course-availability check drops a raw POST parameter straight into a WHERE clause, unauthenticated, with nothing in front of it — no login page to get past first.
CVE-2026-3141: FormGent Unauthenticated Arbitrary File Deletion
A realpath() call on a directory that hasn't been created yet returns false — and a WordPress plugin's own path-traversal guard treats that as proof a request is safe.
CVE-2026-2519: Bookly Unauthenticated Price Manipulation
A tips field with no floor and no ceiling lets an anonymous visitor book a $100 service for $0.00, verified all the way down to the database row.
CVE-2026-1555: WebStack WordPress Theme Unauthenticated File Upload RCE
The code declares an image-extension allowlist and then never actually checks a file against it — the attacker's own filename decides what lands in the uploads directory.
CVE-2025-68613: n8n Expression Sandbox Escape to Unauthenticated RCE
A workflow-automation platform's JavaScript expression evaluator becomes full remote code execution with no login at all — actively exploited in the wild.
CVE-2025-55182: React Server Components Unauthenticated RCE ("React2Shell")
A maximum-severity CVE — a crafted deserialization payload against React Server Components turns into remote code execution, with output smuggled back through an HTTP redirect header.
CVE-2025-54068: Laravel Livewire Unauthenticated RCE
A component property's type in Livewire's client-state format is all it takes for unauthenticated remote code execution.
CVE-2025-35939: Craft CMS Unauthenticated Session-File Content Injection
An unauthenticated request writes arbitrary attacker content, unsanitized, into a real PHP session file on disk — a KEV-listed CVE that had no public PoC before this lab.
CVE-2025-24813: Apache Tomcat Session Deserialization RCE
Actively exploited in the wild — two Tomcat misconfigurations combine to let an attacker plant and trigger arbitrary Java deserialization.