
pd-agent
ProjectDiscovery Cloud - Agent

ProjectDiscovery Cloud - Agent

PoC for CVE-2021-41277

Proof-of-concept exploit for CVE-2022-22536, demonstrating HTTP request smuggling and cache poisoning against SAP NetWeaver servers to compromise…

PoC for CVE-2022-41876

(CVE-2024-33559) The XStore theme for WordPress is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack…

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

Blackout — The Official Blackout Public FAFO Repo.

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

PoC exploit for CVE-2025-34282 - ThingsBoard SSRF via SVG Image Upload

POC for deserialization of untrusted data in wazuh leading to RCE

Proof-of-concept demonstrating a stored XSS vulnerability in Juzaweb CMS v5.0.0 via the banner ads HTML field, leading to arbitrary script execution…

Exploit for Grafana directory traversal (CVE-2021-43798) allowing local file read via crafted plugin path. Includes usage instructions and references.

Reflected Cross-Site Scripting in TOTVS Fluig Plataform 1.6.X - 1.8.1

Proof-of-concept exploit for CVE-2025-64095 targeting DNN CMS, enabling unauthenticated file upload and overwrite to deface sites or inject XSS…

DOM-based Cross-Site Scripting (XSS) Vulnerability in novel V3.5.0 (CWE-79)

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

Proof-of-concept exploit for CVE-2023-1177, a path traversal vulnerability in MLflow, demonstrating unauthorized file access via crafted model names.