
misp-galaxy
Clusters and elements to attach to MISP events or attributes (like threat actors)

Clusters and elements to attach to MISP events or attributes (like threat actors)

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

A curated list of AI Security materials and resources for Pentesters, Bug Hunters, and Security Researchers.

Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts.…

Proof-of-concept exploit for CVE-2026-44578 that reproduces the vulnerable condition, enabling security researchers to validate affected systems and…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Proof-of-concept exploit for CVE-2026-73292: CSRF attack on Semaphore UI password change endpoint, serving a malicious page that silently resets an…

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

Windows Defender patch bypass PoC for CVE-2026-50656 (RoguePlanet), demonstrating exploitability on Windows 11 25H2 and Server 2025 despite…

The poc of CVE-2026-23744

CVE-2026-20685 - Draft or TODO

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Exploit PoCs for CVE-2025-30374, a Taipy class pollution bug, demonstrating RCE, reflected XSS, DoS, and OpenAI credential leakage with Docker-based…

PoC simulation of a critical CCSDS telecommand replay vulnerability in satellite command systems, demonstrating missing sequence-number validation…