On this page
CWE-94: Improper Control of Generation of Code ('Code Injection')
Weakness Summary
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
- Canonical source: MITRE CWE-94 (opens in a new tab)
- Published Atomicorp CVE observations: 277
- Distinct affected products in those observations: 205
- Active Atomicorp rules associated with this weakness: 109
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2014-8877 | WordPress Plugin CM Download Manager 2.0.0 - Code Injection | cm download manager | Attack Blocked by Atomicorp | 340087 , 340095 , 390726 , 392301 , 392647 , 392648 |
| CVE-2022-22947 | Spring Cloud Gateway Code Injection | spring cloud gateway | Attack Blocked by Atomicorp | 344370 , 393655 |
| CVE-2022-24816 | GeoServer <1.2.2 - Remote Code Execution | jai-ext | Attack Blocked by Atomicorp | 337209 , 337210 , 337211 , 340121 , 344360 , 344370 , 380026 |
| CVE-2024-4040 | CrushFTP VFS - Sandbox Escape LFR | crushftp | Attack Blocked by Atomicorp | 392301 |
| CVE-2025-32432 | CraftCMS - Remote Code Execution | craftcms | Attack Blocked by Atomicorp | 344365 |
| CVE-2025-49132 | Pterodactyl Panel - Remote Code Execution | panel | Attack Blocked by Atomicorp | 340007 |
| CVE-2025-59528 | Flowise - Remote Code Execution | flowise | Attack Blocked by Atomicorp | 345240 , 380026 |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | dbgate | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 360151 , 380026 |
| CVE-2026-53576 | Kestra <= 1.3.20 - Remote Code Execution | kestra | Attack Blocked by Atomicorp | 391213 |
| CVE-2026-53753 | Crawl4AI <= 0.8.6 - Remote Code Execution | crawl4ai | Attack Blocked by Atomicorp | 350147 , 360151 , 380026 , 393655 |
| CVE-2026-8984 | Unauthenticated RCE | maxicharger single charger firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2019-10758 | mongo-express Remote Code Execution | mongo-express | Attack Blocked by Atomicorp | 345240 , 360151 , 380026 |
| CVE-2021-21345 | XStream < 1.4.16 - Remote Code Execution | xstream | Attack Blocked by Atomicorp | 344363 , 344366 |
| CVE-2025-23211 | Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCE | recipes | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2026-55565 | Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression) | yamcs | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-55634 | Pimcore: Remote Code Execution via DataObject Class-Definition Field Name | pimcore | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8481 | Remote Code Execution via Code Validation Endpoint | langflow | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2009-1151 | PhpMyAdmin Scripts - Remote Code Execution | phpmyadmin | Attack Blocked by Atomicorp | 340029 , 344360 |
| CVE-2014-6287 | HTTP File Server <2.3c - Remote Command Execution | http file server | Attack Blocked by Atomicorp | 390613 , 390614 |
| CVE-2015-1635 | Microsoft Windows 'HTTP.sys' - Remote Code Execution | Windows 7 | Attack Blocked by Atomicorp | 363434 |
| CVE-2017-7402 | Pixie 1.0.4 - Arbitrary File Upload | pixie | Detected by Atomicorp | 345493 |
| CVE-2017-9841 | PHPUnit - Remote Code Execution | phpunit | Attack Blocked by Atomicorp | 392648 , 393782 |
| CVE-2018-1273 | Spring Data Commons - Remote Code Execution | spring data commons | Attack Blocked by Atomicorp | 344360 , 344370 |
| CVE-2018-17173 | LG Supersign EZ CMS - Remote Code Execution | supersign cms | Attack Blocked by Atomicorp | 340014 , 340029 , 344361 , 344363 , 344370 |
| CVE-2019-13372 | D-Link Central WiFi Manager CWM(100) - Remote Code Execution | central wifimanager | Attack Blocked by Atomicorp | 344370 |
| CVE-2019-16759 | vBulletin 5.0.0-5.5.4 - Remote Command Execution | vbulletin | Attack Blocked by Atomicorp | 341245 |
| CVE-2020-10257 | ThemeREX Addons - Remote Code Execution | themerex | Detected by Atomicorp | 377360 |
| CVE-2020-11546 | SuperWebmailer 7.21.0.01526 - Remote Code Execution | superwebmailer | Attack Blocked by Atomicorp | 340095 , 393655 |
| CVE-2020-35131 | Cockpit CMS 0.6.1 - Remote Code Execution | cockpit | Attack Blocked by Atomicorp | 340095 |
| CVE-2021-25003 | WordPress WPCargo Track & Trace <6.9.0 - Remote Code Execution | wpcargo track & trace | Detected by Atomicorp | 331324 |
| CVE-2021-41749 | CraftCMS SEOmatic - Server-Side Template Injection | seomatic | Attack Blocked by Atomicorp | 390719 |
| CVE-2022-1609 | The School Management < 9.9.7 - Remote Code Execution | school management | Attack Blocked by Atomicorp | 340095 , 344361 |
| CVE-2022-22954 | VMware Workspace ONE Access - Server-Side Template Injection | identity manager | Attack Blocked by Atomicorp | 344360 , 344361 , 344363 , 344370 , 393655 |
| CVE-2022-29078 | Node.js Embedded JavaScript 3.1.6 - Template Injection | ejs | Attack Blocked by Atomicorp | 340014 , 340193 , 344370 , 345240 , 380026 |
| CVE-2022-3236 | Sophos Firewall <= 19.0 MR1 - Remote Code Execution | firewall | Attack Blocked by Atomicorp | 344361 , 344364 |
| CVE-2022-45699 | APsystems ECU-R Firmware - Command Injection | ecu-r firmware | Attack Blocked by Atomicorp | 344364 , 344366 |
| CVE-2023-0297 | PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE) | pyload | Attack Blocked by Atomicorp | 340095 |
| CVE-2023-25717 | Ruckus Wireless Admin - Remote Code Execution | ruckus wireless admin | Attack Blocked by Atomicorp | 344363 , 393655 |
| CVE-2023-34990 | FortiWLM - Directory Traversal | fortiwlm | Attack Blocked by Atomicorp | 340007 |
| CVE-2023-41892 | CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution | craft cms | Attack Blocked by Atomicorp | 344365 |
| CVE-2023-6553 | Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution | backup migration | Attack Blocked by Atomicorp | 301106 |
| CVE-2024-0195 | SpiderFlow Crawler Platform - Remote Code Execution | spider-flow | Attack Blocked by Atomicorp | 337209 , 337210 , 337211 , 340095 |
| CVE-2024-21650 | XWiki < 4.10.20 - Remote code execution | xwiki | Attack Blocked by Atomicorp | 340130 |
| CVE-2024-23692 | Rejetto HTTP File Server - Template injection | http file server | Attack Blocked by Atomicorp | 344364 , 344366 , 390703 , 390722 |
| CVE-2024-31823 | ecommerce-codeigniter-bootstrap Arbitrary Code Execution Vulnerability | ecommerce-codeigniter-bootstrap | Attack Blocked by Atomicorp | 344360 |
| CVE-2024-3408 | D-Tale 3.10.0 - 3.15.1 - Authentication Bypass & Remote Code Execution | dtale | Attack Blocked by Atomicorp | 340087 , 340095 |
| CVE-2024-37014 | Langflow <= 1.0.12 - Remote Code Execution | langflow | Attack Blocked by Atomicorp | 340095 , 344370 |
| CVE-2024-45507 | Apache OFBiz - Remote Code Execution | ofbiz | Attack Blocked by Atomicorp | 340162 , 340163 , 344370 |
| CVE-2024-50498 | WP Query Console <= 1.0 - Remote Code Execution | wp query console | Attack Blocked by Atomicorp | 340095 |
| CVE-2025-13486 | Advanced Custom Fields Extended < 0.9.2 - Remote Code Execution | Advanced Custom Fields: Extended | Detected by Atomicorp | 377360 |
| CVE-2025-24893 | XWiki Platform - Remote Code Execution | xwiki | Attack Blocked by Atomicorp | 340023 , 347009 |
| CVE-2025-29306 | FoxCMS v.1.2.5 - Remote Code Execution | foxcms | Attack Blocked by Atomicorp | 344360 , 344370 , 347009 , 393655 |
| CVE-2025-3248 | Langflow AI - Unauthenticated Remote Code Execution | langflow | Attack Blocked by Atomicorp | 340095 , 344360 , 344370 |
| CVE-2026-31040 | stata-mcp Code Injection Vulnerability | stata-mcp | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-3300 | Everest Forms Pro <= 1.9.12 - Unauthenticated RCE via Calculation Formula Injection | Everest Forms Pro | Attack Blocked by Atomicorp | 300021 |
| CVE-2026-3584 | WordPress Kali Forms <= 2.4.9 - Remote Code Execution | kali-forms | Attack Blocked by Atomicorp | 300223 |
| CVE-2026-38431 | erpnext Code Injection Vulnerability | erpnext | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override | yamcs | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-55559 | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) | yamcs | Attack Blocked by Atomicorp | 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-60004 | Gitea <= 1.27.0 - Pre-Auth Remote Code Execution | gitea | Attack Blocked by Atomicorp | 330907 , 330908 , 330909 |
| CVE-2026-67919 | Halo 2.25.4 Arbitrary Code Execution Vulnerability | - | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-67926 | JeecgBoot v.3.9.2 Arbitrary Code Execution Vulnerability | - | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-75411 | JeecgBoot v3.9.2 Code Injection Vulnerability | - | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75414 | In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability | - | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-77806 | SPIP < 4.4.22 - Unauthenticated RCE | SPIP | Attack Blocked by Atomicorp | 380018 , 380026 |
| CVE-2026-9198 | IBM Langflow - Remote Code Execution | langflow | Attack Blocked by Atomicorp | 300008 , 340095 |
| CVE-2026-6875 | ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE | servicenow | Attack Blocked by Atomicorp | 380026 |
| CVE-2026-70477 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability | flowise | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-88062 | OmniRoute ACP Custom-Agent Remote Code Execution (RCE) | OmniRoute | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2024-9264 | Grafana Post-Auth DuckDB - SQL Injection To File Read | grafana | Attack Blocked by Atomicorp | 340016 , 344360 , 344370 |
| CVE-2025-62593 | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | ray | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-44262 | Scramble Laravel - Remote Code Execution | scramble | Attack Blocked by Atomicorp | 341245 , 380026 , 380122 |
| CVE-2026-45272 | MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File | talebook | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-46442 | Flowise < 3.1.2 - node-custom-function Unauthorized RCE | flowise | Attack Blocked by Atomicorp | 345240 |
| CVE-2026-69256 | Flowise: Remote Code Execution Vulnerability in CSVAgent | Flowise | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-82244 | Budibase before 3.41.3 Remote Code Execution via Plugin eval() | server | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390719 , 393655 |
| CVE-2013-1965 | Apache Struts2 S2-012 RCE | struts | Attack Blocked by Atomicorp | 337207 , 337209 , 337211 , 344360 |
| CVE-2017-20251 | WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API | Woody Code Snippets | Attack Blocked by Atomicorp | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2018-25114 | osCommerce 2.3.4.1 - Remote Code Execution | Online Merchant | Attack Blocked by Atomicorp | 340023 , 340095 , 344360 , 344370 |
| CVE-2018-25357 | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php | dolibarr erp/crm | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 |
| CVE-2026-27174 | MajorDoMo - Unauthenticated RCE | majordomo | Attack Blocked by Atomicorp | 344360 , 344370 , 347009 , 390904 |
| CVE-2026-29014 | MetInfo CMS <= 8.1 - Remote Code Execution | metinfo | Attack Blocked by Atomicorp | 340121 , 344363 , 360152 , 380026 , 390635 , 393655 |
| CVE-2026-58138 | Orkes Conductor 3.21.21-3.30.1 - Remote Code Execution | conductor | Attack Blocked by Atomicorp | 337209 , 337211 , 344366 , 380026 , 393655 |
| CVE-2026-65008 | Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData | grav | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655 |
| CVE-2026-70553 | MaxSite CMS Unauthenticated RCE via Install Endpoint | MaxSite CMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-27760 | OpenCATS - Command Injection | OpenCATS | Attack Blocked by Atomicorp | 344363 , 344370 |
| CVE-2026-41179 | RClone RC - Command Injection | rclone | Attack Blocked by Atomicorp | 340014 , 344370 |
| CVE-2025-49029 | WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution | Custom Login And Signup Widget | Detected by Atomicorp | 377360 |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection | yamcs | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-55511 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSql | yamcs | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter | core-geonetwork | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | Remote API | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-34448 | SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop cl | siyuan | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | omnigent | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-69251 | Flowise RCE via TypeORM DataSource | Flowise | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-73485 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | flowise | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73486 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV | flowise | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73487 | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent | flowise | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-1302 | JSONPath Plus < 10.3.0 - Remote Code Execution | jsonpath-plus | Attack Blocked by Atomicorp | 345240 , 346755 , 360151 , 380026 |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | FUXA | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-77956 | EEx template evaluation of prompt content in AshAi enables remote code execution | ash ai | Attack Blocked by Atomicorp | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2017-9822 | DotNetNuke 5.0.0 - 9.3.0 - Cookie Deserialization Remote Code Execution | dotnetnuke | Attack Blocked by Atomicorp | 344365 , 344370 |
| CVE-2019-15642 | Webmin < 1.920 - Authenticated Remote Code Execution | webmin | Attack Blocked by Atomicorp | 344362 , 344366 |
| CVE-2019-9082 | ThinkPHP < 3.2.4 - Remote Code Execution | thinkphp | Attack Blocked by Atomicorp | 344361 , 393753 |
| CVE-2020-8163 | Ruby on Rails <5.0.1 - Remote Code Execution | rails | Attack Blocked by Atomicorp | 340023 , 344360 , 344370 , 347009 , 390724 |
| CVE-2021-22053 | Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Execution | spring cloud netflix | Attack Blocked by Atomicorp | 337209 , 337211 , 340087 , 340193 |
| CVE-2022-4223 | pgAdmin < 6.17 - Unauthenticated Remote Code Execution | pgadmin 4 | Attack Blocked by Atomicorp | 393655 |
| CVE-2024-28253 | OpenMetaData - SpEL Injection in PUT /api/v1/policies | openmetadata | Attack Blocked by Atomicorp | 337209 , 337210 , 337211 , 340095 |
| CVE-2024-41667 | OpenAM<=15.0.3 FreeMarker - Template Injection | OpenAM | Attack Blocked by Atomicorp | 344360 , 392647 , 393655 |
| CVE-2026-34197 | Apache ActiveMQ - Remote Code Execution | activemq | Attack Blocked by Atomicorp | 330925 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-40466 | Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypass | activemq | Attack Blocked by Atomicorp | 330925 , 340162 , 340163 |
| CVE-2026-45505 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypass | activemq | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-48017 | DbGate: Remote Code Execution via functionName injection in loadReader endpoint | dbgate | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-55585 | QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr() | qwed-verification | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-62675 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools | omnigent | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-78834 | Code Injection | - | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2021-47938 | ImpressCMS 1.4.2 Remote Code Execution via Autotasks | ImpressCMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2021-47939 | Evolution CMS 3.1.6 Authenticated Remote Code Execution via Module Creation | Evolution CMS | Attack Blocked by Atomicorp | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2022-50944 | Aero CMS 0.0.1 PHP Code Injection via posts.php | Aero CMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-25856 | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface | openbullet2 | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-28797 | RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compone | ragflow | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-47722 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml | nebula-mesh | Attack Blocked by Atomicorp | 340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008 |
| CVE-2026-49143 | BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler | browserstack-runner | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-64850 | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | grav | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655 |
| CVE-2026-69100 | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution | lamp-cloud | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72819 | Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload | grav | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-76836 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass | AzuraCast | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-82278 | BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once | bisheng | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-85604 | Grav before 2.0.19 Remote Code Execution via sort filter | grav | Attack Blocked by Atomicorp | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-85610 | OpenPanel before 2.3.0 Remote Code Execution via chart formulas | openpanel | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-86732 | Craft CMS before 5.10.12 Remote Code Execution via element-index | cms | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2021-32820 | Express-handlebars - Local File Inclusion | express handlebars | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2026-42785 | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting | OpenKM Community Edition | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-56703 | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO | adminer | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655 |
| CVE-2026-61523 | WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor | WebsiteBaker CMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-65693 | Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates | microweber | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-69088 | Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint | grav | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-76635 | baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php | basercms | Attack Blocked by Atomicorp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2021-39144 | XStream 1.4.18 - Remote Code Execution | xstream | Attack Blocked by Atomicorp | 344363 |
| CVE-2026-22244 | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE | openmetadata | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-34725 | dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration | dbgate | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2019-3759 | RSA IG&L Aveksa 7.1.1 - Remote Code Execution | rsa identity governance and lifecycle | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2024-43425 | Moodle - Remote Code Execution | moodle | Attack Blocked by Atomicorp | 340095 , 360152 |
| CVE-2026-42588 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector | activemq | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-47398 | PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20 | PraisonAI | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71320 | Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props | nuxt | Attack Blocked by Atomicorp | 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-6204 | DELMIA Apriso - Command Injection | delmia apriso | Attack Blocked by Atomicorp | 340095 , 341245 , 344361 , 344365 , 344366 , 347019 , 390724 |
| CVE-2026-65937 | WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI | whatsup gold | Attack Blocked by Atomicorp | 340147 , 340148 , 340149 |
| CVE-2026-66738 | SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite | SPIP | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 |
| CVE-2006-0887 | PHPLib < 7.4 - SQL Injection | phplib | Attack Blocked by Atomicorp | 340017 , 340181 , 341245 , 344370 , 360147 , 360148 |
| CVE-2008-1059 | WordPress Sniplets 1.1.2 - Local File Inclusion | sniplets plugin | Attack Blocked by Atomicorp | 336461 , 340007 , 344360 , 381206 |
| CVE-2009-4223 | KR-Web <=1.1b2 - Remote File Inclusion | kr-php web content server | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2010-2918 | Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion | com joomla visites | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2014-6389 | PHPCompta/NOALYSS 6.7.1 5638 - Remote Command Execution | phpcompta/noalyss | Attack Blocked by Atomicorp | 340128 , 344363 , 350147 , 380018 , 390726 , 392301 , 392647 , 392648 |
| CVE-2026-46581 | mojarra Path Traversal Vulnerability | mojarra | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2024-11740 | Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Execution | download manager | Attack Blocked by Atomicorp | 344370 |
| CVE-2024-46507 | Yeti Platform < 2.1.12 - Server-Side Template Injection to RCE | yeti | Attack Blocked by Atomicorp | 340130 , 360151 |
| CVE-2023-46818 | ISPConfig - PHP Code Injection | ispconfig | Attack Blocked by Atomicorp | 340095 |
| CVE-2026-13392 | ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) | ElementsKit Elementor Addons | Attack Blocked by Atomicorp | 340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2024-5082 | Nexus Repository 2 - Remote Code Execution | Nexus Repository | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2026-77939 | Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint | flextype | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5739 | PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injection | PowerJob | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-39311 | Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG Attachments | Trilium | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340099 , 341099 , 342259 , 344363 |
| CVE-2026-44287 | FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassable | FastGPT | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2022-3242 | Microweber <1.3.2 - Cross-Site Scripting | microweber | Attack Blocked by Atomicorp | 340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73084 | Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint | activepieces | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2025-13786 | taosir WTCMS index.php fetch code injection | wtcms | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390768 , 393655 |
| CVE-2025-13792 | Qualitor getResumo.php eval code injection | the file /html/st/stdeslocamento/request/getResumo.php | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-3395 | MaxSite CMS <=109.1 - Remote Code Execution | maxsite cms | Attack Blocked by Atomicorp | 344364 , 344370 |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | icms2 | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-5631 | assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection | gpt-researcher | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-76760 | chenhg5 cc-connect webhook.go authenticate code injection | cc-connect | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-82598 | SeaCMS Template search.php parseIf code injection | SeaCMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-85137 | SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection | SeaCMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2014-8677 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | Attack Blocked by Atomicorp | 331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647 |
| CVE-2024-11587 | idcCMS V1.60 - Cross-Site Scripting | idccms | Attack Blocked by Atomicorp | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 |
| CVE-2024-28397 | pyload-ng js2py - Remote Code Execution | pyload | Attack Blocked by Atomicorp | 340014 , 344363 , 346755 , 360151 , 380026 |
| CVE-2025-2127 | JoomlaUX JUX Real Estate 3.4.0 - Reflected XSS | jux real estate | Attack Blocked by Atomicorp | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-2709 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida erp-nc | Attack Blocked by Atomicorp | 333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148 |
| CVE-2025-2710 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida erp-nc | Attack Blocked by Atomicorp | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-2711 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida erp-nc | Attack Blocked by Atomicorp | 333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148 |
| CVE-2025-2712 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida erp-nc | Attack Blocked by Atomicorp | 333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148 |
| CVE-2026-5808 | openstatusHQ openstatus Onboarding Endpoint client.tsx cross site scripting | openstatus | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10153 | westboy CicadasCMS AbstractCacheManager.java search cross site scripting | CicadasCMS | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10173 | Orthanc Explorer 2 URL StudyList.vue cross site scripting | Explorer 2 | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10289 | code-projects Hotel and Tourism Reservation System tour.php cross site scripting | Hotel and Tourism Reservation System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10301 | itsourcecode Fees Management System index.php cross site scripting | Fees Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-10810 | itsourcecode Fees Management System navbar.php cross site scripting | Fees Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-11436 | Mage AI Sign-in Flow index.tsx useMutation cross site scripting | Mage AI | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-11512 | itsourcecode Hospital Management System billing.php cross site scripting | Hospital Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-11518 | SourceCodester Inventory System User Management users.php cross site scripting | Inventory System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 380106 |
| CVE-2026-16220 | code-projects Online Examination System account.php cross site scripting | Online Examination System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16229 | itsourcecode Courier Management System index.php cross site scripting | Courier Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-16485 | SourceCodester Class and Exam Timetabling System class.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16486 | SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-18968 | ttttonyhe OBlog tags.php cross site scripting | OBlog | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-19378 | code-projects Task Management System CommentSave.php cross site scripting | Task Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19932 | DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection | Notice-System-Managent | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-19958 | iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection | pptr-mcp | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-19998 | code-projects Online Shopping System offersmail.php cross site scripting | Online Shopping System | Attack Blocked by Atomicorp | 333140 , 333141 , 340147 , 340148 , 341256 , 346755 |
| CVE-2026-5825 | code-projects Simple Laundry System delmemberinfo.php cross site scripting | Simple Laundry System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-5826 | code-projects Simple IT Discussion Forum edit-category.php cross site scripting | Simple IT Discussion Forum | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-75077 | SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-75078 | SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78054 | SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78055 | SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78059 | SourceCodester Stock Management System printOrder.php cross site scripting | Stock Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78060 | SourceCodester Stock Management System getOrderReport.php cross site scripting | Stock Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78166 | provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection | kafka-ui | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-79793 | code-projects Online Shopping System sumit_form.php cross site scripting | Online Shopping System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82601 | SeaCMS err.php cross site scripting | SeaCMS | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-82625 | code-projects Simple Inventory System User Registration register.php cross site scripting | Simple Inventory System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82664 | yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting | GEOFlow | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82700 | code-projects Online Shopping System Newsletter Subscription offersmail.php cross site scripting | Online Shopping System | Attack Blocked by Atomicorp | 333140 , 333141 , 340147 , 340148 , 341256 , 346755 |
| CVE-2026-85021 | langgenius dify Splash Layout splash.tsx router.replace cross site scripting | dify | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85382 | light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scripting | cms | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-86216 | code-projects Hotel and Tourism Reservation in PHP details.php cross site scripting | Hotel and Tourism Reservation in PHP | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86244 | FastAdmin User Controller User.php login cross site scripting | FastAdmin | Attack Blocked by Atomicorp | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86278 | SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.php cross site scripting | Syllabus-Aligned Learning Management & Examination System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-86294 | SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting | Simple Traffic Offense System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-86668 | aircheng-org iWebShop-5 pic.php uploadFile cross site scripting | iWebShop-5 | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-87926 | Rizwan17 inventory-management-system Login Page index.php cross site scripting | inventory-management-system | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-9302 | 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection | vps-inventory-monitoring | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9415 | code-projects Employee Management System eloginwel.php cross site scripting | Employee Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9416 | code-projects Employee Management System myprofile.php cross site scripting | Employee Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9417 | code-projects Employee Management System myprofileup.php cross site scripting | Employee Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9418 | code-projects Employee Management System changepassemp.php cross site scripting | Employee Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9419 | code-projects Employee Management System empproject.php cross site scripting | Employee Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9448 | code-projects Employee Management System applyleave.php cross site scripting | Employee Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9518 | hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent cross site scripting | CodeIgniter-StudentManagementSystem | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9519 | stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site scripting | pingvin-share | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9520 | blitz-js blitz Sign-in LoginForm.tsx cross site scripting | blitz | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-9527 | itsourcecode Electronic Judging System judges.php cross site scripting | Electronic Judging System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9566 | teableio teable Sign-up LoginPage.tsx cross site scripting | teable | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10228 | raisulislamg4 student_management_system_by_php admission_form_check.php cross site scripting | student management system by php | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10234 | Mettle sendportal Campaign webview cross site scripting | sendportal | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10244 | SourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scripting | Pharmacy Sales and Inventory System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10245 | SourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scripting | Pharmacy Sales and Inventory System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10246 | SourceCodester Pharmacy Sales and Inventory System main create_medicine_presentation cross site scripting | Pharmacy Sales and Inventory System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10247 | SourceCodester Pharmacy Sales and Inventory System main create_generic_name cross site scripting | Pharmacy Sales and Inventory System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10567 | 1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting | CordysCRM | Attack Blocked by Atomicorp | 333140 , 333141 |
| CVE-2026-16155 | SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16156 | SourceCodester Class and Exam Timetabling System forexam.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16202 | SourceCodester Class and Exam Timetabling System CYS.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16203 | SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19209 | SourceCodester Photo Share Website index.php home cross site scripting | Photo Share Website | Attack Blocked by Atomicorp | 333140 , 333141 , 340147 , 340148 , 342259 , 350147 , 350148 |
| CVE-2026-19922 | code-projects Online Shopping System checkout.php cross site scripting | Online Shopping System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19964 | Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection | Jij-MCP-Server | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5806 | code-projects Easy Blog Site update.php cross site scripting | Easy Blog Site | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-5810 | SourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting | Sales and Inventory System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-7222 | code-projects Coaching Management System Complaint Form complaint.php cross site scripting | Coaching Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-81835 | RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection | Roo-Code | Attack Blocked by Atomicorp | 340014 , 344360 , 347009 , 393655 |
| CVE-2026-82483 | coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scripting | Coppermine Photo Gallery | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82488 | Beetel 450TC3 User Management cross site scripting | 450TC3 | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82622 | code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting | Employee Leave Managing System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-82666 | yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection | GEOFlow | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-84437 | OpenCart Autocomplete Workflow address.php cross site scripting | OpenCart | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 340247 , 340248 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-84438 | OpenCart Autocomplete Workflow edit.php cross site scripting | OpenCart | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85022 | langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting | dify | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85207 | itsourcecode Online Medicine Delivery System index.php cross site scripting | Online Medicine Delivery System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86181 | code-projects Task Management System User Profile Update UpdateUserProfile.php cross site scripting | Task Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86301 | code-projects Hospital Information System Patient Management editPatient.php cross site scripting | Hospital Information System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86644 | star7th showdoc API Page Save Endpoint editormd.js cross site scripting | showdoc | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10112 | sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting | STUDENT-MANAGEMENT-SYSTEM | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-10514 | 1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting | CordysCRM | Attack Blocked by Atomicorp | 333140 |
| CVE-2026-10529 | westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting | CicadasCMS | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 344370 , 346755 , 350147 , 350148 |
| CVE-2026-11434 | FluentCMS Blocks Plugin blocks cross site scripting | FluentCMS | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-11468 | SourceCodester Hospitals Patient Records Management System page room_types cross site scripting | Hospitals Patient Records Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16205 | Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting | CMS | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19110 | DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting | DataGear | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19207 | PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting | Company Visitor Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-5834 | code-projects Online Shoe Store admin_running.php cross site scripting | Online Shoe Store | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-5835 | code-projects Online Shoe Store admin_football.php cross site scripting | Online Shoe Store | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-5836 | code-projects Online Shoe Store admin_product.php cross site scripting | Online Shoe Store | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-9564 | SourceCodester/oretnom23 Hospitals Patient Records Management System view_patient cross site scripting | Hospitals Patient Records Management System | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9608 | QianFox FoxCMS Administrator Backend edit cross site scripting | FoxCMS | Attack Blocked by Atomicorp | 340095 , 346755 |
| CVE-2026-78187 | Piwigo Public Authentication cross site scripting | Piwigo | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 300008 | Active | disruptive (deny) |
| 300021 | Active | disruptive (deny) |
| 300223 | Active | disruptive (deny) |
| 301106 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 330907 | Active | disruptive (deny) |
| 330908 | Active | disruptive (deny) |
| 330909 | Active | disruptive (deny) |
| 330925 | Active | disruptive (deny) |
| 331028 | Active | disruptive (deny) |
| 331324 | Active | non-disruptive (pass) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 336461 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 337207 | Active | disruptive (deny) |
| 337209 | Active | disruptive (deny) |
| 337210 | Active | disruptive (deny) |
| 337211 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340087 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340099 | Active | disruptive (deny) |
| 340121 | Active | disruptive (deny) |
| 340128 | Active | disruptive (deny) |
| 340130 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340155 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340159 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340181 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 340247 | Active | disruptive (deny) |
| 340248 | Active | disruptive (deny) |
| 341099 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341155 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 341266 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344380 | Active | disruptive (deny) |
| 344382 | Active | disruptive (deny) |
| 344385 | Active | disruptive (deny) |
| 345240 | Active | disruptive (deny) |
| 345493 | Active | non-disruptive (pass) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 347019 | Active | disruptive (deny) |
| 347198 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 360151 | Active | disruptive (deny) |
| 360152 | Active | disruptive (deny) |
| 360153 | Active | disruptive (deny) |
| 363434 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380018 | Active | disruptive (deny) |
| 380026 | Active | disruptive (deny) |
| 380106 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 381206 | Active | disruptive (deny) |
| 390501 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390613 | Active | disruptive (deny) |
| 390614 | Active | disruptive (deny) |
| 390635 | Active | disruptive (deny) |
| 390703 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390719 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390768 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 391213 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 393753 | Active | disruptive (deny) |
| 393782 | Active | disruptive (deny) |
| 398008 | Active | non-disruptive (pass) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-242 (opens in a new tab) , CAPEC-35 (opens in a new tab) , CAPEC-77 (opens in a new tab)