Atomicorp WAF Research Notes
Research Update - 2026-07-22
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
- CVE-2010-0219 - Apache Axis2 Default Login - rules observed: 920420, 949110, 980170
- CVE-2024-22476 - Intel Neural Compressor <2.5.0 - SQL Injection - rules observed: 341245
- CVE-2024-27115 - SOPlanning - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2024-42640 - Angular-Base64-Upload - Remote Code Execution - rules observed: 932260, 949110, 980170
- CVE-2024-46506 - NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2024-8353 - GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection - rules observed: 920420, 949110, 980170
- CVE-2025-34028 - Commvault - SSRF via /commandcenter/deployWebpackage.do - rules observed: 920420, 949110, 980170
- CVE-2025-34077 - WordPress Pie Register <= 3.7.1.4 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2026-10520 - Ivanti Sentry - OS Command Injection - rules observed: 920420, 949110, 980170
- CVE-2026-28409 - WeGIA <= 3.6.4 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2026-8054 - dotCMS Core Publish Audit API - Unauthenticated SQL Injection - rules observed: 340145
- CVE-2025-52207 - MikoPBX - Unrestricted File Upload - rules observed: 920420, 949110, 980170
- CVE-2026-25512 - Group-Office < 26.0.5 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2016-9682 - Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection - rules observed: 930120, 949110, 980170
- CVE-2017-1000486 - Primetek Primefaces 5.x - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2017-14097 - Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control - rules observed: 330791
- CVE-2017-16935 - Ametys CMS 4.0.2 - Password Reset - rules observed: 920420, 949110, 980170
- CVE-2018-12463 - Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection - rules observed: 920470, 980170
- CVE-2018-17207 - WordPress Duplicator Plugin < 1.2.42 - Arbitrary Code Execution - rules observed: 920420, 949110, 980170
- CVE-2018-18923 - Ticketly 1.0 - ‘kind_id’ SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2018-19410 - PRTG Network Monitor - Local File Inclusion - rules observed: 920420, 949110, 980170
- CVE-2018-2894 - Oracle WebLogic Server - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2018-7602 - Drupal - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2019-12279 - Nagios XI 5.6.1 - SQL injection - rules observed: 920420, 949110, 980170
- CVE-2019-12989 - Citrix SD-WAN and NetScaler SD-WAN - SQL Injection - rules observed: 340016
- CVE-2019-18818 - strapi CMS <3.0.0-beta.17.5 - Admin Password Reset - rules observed: 942290, 949110, 980170
- CVE-2019-3929 - Barco/AWIND OEM Presentation Platform - Remote Command Injection - rules observed: 920420, 949110, 980170
- CVE-2019-7192 - QNAP QTS and Photo Station 6.0.3 - Remote Command Execution - rules observed: 920420, 949110, 980170
- CVE-2019-7194 - QNAP Photo Station < 6.0.3 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2019-7195 - QNAP Photo Station - Path Traversal - rules observed: 920420, 949110, 980170
- CVE-2019-9874 - Sitecore Experience Platform - Deserialization of Untrusted Data - rules observed: 920420, 949110, 980170
- CVE-2020-13638 - rConfig 3.9 - Authentication Bypass(Admin Login) - rules observed: 920420, 949110, 980170
- CVE-2020-13942 - Apache Unomi <1.5.2 - Remote Code Execution - rules observed: 340095
- CVE-2020-16846 - SaltStack <=3002 - Shell Injection - rules observed: 920420, 949110, 980170
- CVE-2020-25223 - Sophos UTM Preauth - Remote Code Execution - rules observed: 340014
- CVE-2020-25990 - WebsiteBaker 2.12.2 - ‘display_name’ SQL Injection (authenticated) - rules observed: 920420, 949110, 980170
- CVE-2020-28429 - geojson2kml - Command Injection - rules observed: 344361
- CVE-2020-35131 - Cockpit CMS 0.6.1 - Remote Code Execution - rules observed: 340095
- CVE-2020-35846 - Agentejo Cockpit < 0.11.2 - NoSQL Injection - rules observed: 942290, 949110, 980170
- CVE-2020-36708 - WordPress Epsilon Framework Themes <=2.4.8 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2020-7961 - Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2020-7980 - Satellian Intellian Aptus Web <= 1.24 - Remote Command Execution - rules observed: 344360
- CVE-2020-8772 - WordPress InfiniteWP <1.9.4.5 - Authorization Bypass - rules observed: 920420, 949110, 980170
- CVE-2020-9480 - Apache Spark - Authentication Bypass - rules observed: 340162
- CVE-2021-22005 - VMware vCenter Server - Arbitrary File Upload - rules observed: 330791
- CVE-2021-22502 - Micro Focus Operations Bridge Reporter - Remote Code Execution - rules observed: 344364
- CVE-2021-22707 - EVlink City < R8 V3.4.0.1 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2021-22911 - Rocket.Chat <=3.13 - NoSQL Injection - rules observed: 942290, 949110, 980170
- CVE-2021-22986 - F5 iControl REST - Remote Command Execution - rules observed: 934110, 934190, 949110, 980170
- CVE-2021-25281 - SaltStack Salt <3002.5 - Auth Bypass - rules observed: 340007
- CVE-2021-27856 - FatPipe WARP/IPVPN/MPVPN - Backdoor Account - rules observed: 920420, 949110, 980170
- CVE-2021-28799 - QNAP HBS 3 - Broken Access Control - rules observed: 344360
- CVE-2021-3007 - Laminas Project laminas-http - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2021-3129 - Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution - rules observed: 340007, 340162, 344365
- CVE-2021-33044 - Dahua IPC/VTH/VTO - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2021-36888 - WordPress Image Hover Ultimate - Unauthenticated Settings Update - rules observed: 920420, 949110, 980170
- CVE-2021-38647 - Microsoft Open Management Infrastructure - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2021-40539 - Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution - rules observed: 920420, 949110, 980170
- CVE-2021-41419 - QVIS NVR/DVR - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2021-4374 - WordPress Automatic Plugin - Unauthenticated Options Change - rules observed: 920420, 949110, 980170
- CVE-2021-44427 - Rosario Student Information System Unauthenticated SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2022-0948 - WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection - rules observed: 380122
- CVE-2022-1020 - WordPress WooCommerce <3.1.2 - Arbitrary Function Call - rules observed: 920420, 949110, 980170
- CVE-2022-1040 - Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass - rules observed: 920420, 920540, 949110, 980170
- CVE-2022-1386 - WordPress Fusion Builder <3.6.2 - Server-Side Request Forgery - rules observed: 920420, 949110, 980170
- CVE-2022-22956 - VMware Workspace ONE Access - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2022-22963 - Spring Cloud - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2022-24112 - Apache APISIX - Remote Code Execution - rules observed: 344364
- CVE-2022-24637 - Open Web Analytics 1.7.3 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2022-2487 - Wavlink WN535K2/WN535K3 - OS Command Injection - rules observed: 920420, 949110, 980170
- CVE-2022-25237 - Bonita Web 2021.2 - Authentication/Authorization Bypass - rules observed: 920420, 949110, 980170
- CVE-2022-26138 - Atlassian Questions For Confluence - Hardcoded Credentials - rules observed: 920420, 949110, 980170
- CVE-2022-28219 - Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Execution - rules observed: 344370
- CVE-2022-30525 - Zyxel Firewall - OS Command Injection - rules observed: 344363
- CVE-2022-31125 - Roxy WI v6.1.0.0 - Improper Authentication Control - rules observed: 920420, 949110, 980170
- CVE-2022-31126 - Roxy-WI - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2022-31161 - Roxy-WI - Remote Code Execution - rules observed: 920420, 932260, 949110, 980170
- CVE-2022-31181 - PrestaShop - SQL Injection to Eval Injection - rules observed: 920420, 949110, 980170
- CVE-2022-33198 - WordPress Accordions - Unauthenticated Settings Update - rules observed: 920420, 949110, 980170
- CVE-2022-34487 - ShortCode Addons - Unauthenticated Options Update - rules observed: 920420, 949110, 980170
- CVE-2022-3477 - WordPress tagDiv Composer < 3.5 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2022-35413 - WAPPLES Web Application Firewall <=6.0 - Hardcoded Credentials - rules observed: 920420, 949110, 980170
- CVE-2022-37061 - FLIR AX8 1.46.16 - Remote Command Injection - rules observed: 920420, 949110, 980170
- CVE-2022-40022 - Symmetricom SyncServer Unauthenticated - Remote Command Execution - rules observed: 920420, 949110, 980170
- CVE-2022-47966 - ManageEngine - Remote Command Execution - rules observed: 920420, 949110, 980170
- CVE-2022-47986 - IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution - rules observed: 344364
- CVE-2023-1454 - Jeecg-boot 3.5.0 qurestSql - SQL Injection - rules observed: 340159
- CVE-2023-1671 - Sophos Web Appliance - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2023-1698 - WAGO - Remote Command Execution - rules observed: 920420, 949110, 980170
- CVE-2023-22515 - Atlassian Confluence - Privilege Escalation - rules observed: 920420, 949110, 980170
- CVE-2023-2732 - MStore API <= 3.9.2 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2023-28121 - WooCommerce Payments - Unauthorized Admin Access - rules observed: 920420, 949110, 980170
- CVE-2023-2982 - Miniorange Social Login and Register <= 7.6.3 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2023-34659 - JeecgBoot 3.5.0 - SQL Injection - rules observed: 330791
- CVE-2023-3519 - Citrix NetScaler ADC and NetScaler Gateway - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2023-35813 - Sitecore - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2023-37759 - Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated) - rules observed: 920420, 949110, 980170
- CVE-2023-37999 - HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation - rules observed: 920420, 949110, 980170
- CVE-2023-43654 - PyTorch TorchServe SSRF - rules observed: 920420, 949110, 980170
- CVE-2023-4542 - D-Link DAR-8000-10 - Command Injection - rules observed: 920420, 949110, 980170
- CVE-2023-45852 - Viessmann Vitogate 300 - Remote Code Execution - rules observed: 344360
- CVE-2023-45878 - Gibbon LMS <= v25.0.01 - File Upload to RCE - rules observed: 920420, 949110, 980170
- CVE-2023-6875 - WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass - rules observed: 920420, 949110, 980170
- CVE-2023-6895 - Hikvision IP ping.php - Command Execution - rules observed: 920420, 949110, 980170
- CVE-2024-0799 - Arcserve Unified Data Protection - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2024-12824 - Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change - rules observed: 920420, 949110, 980170
- CVE-2024-1698 - NotificationX <= 2.8.2 - SQL Injection - rules observed: 380122
- CVE-2024-23163 - GestSup - Account Takeover - rules observed: 920420, 949110, 980170
- CVE-2024-23917 - JetBrains TeamCity > 2023.11.3 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2024-24496 - Daily Habit Tracker 1.0 - Broken Access Control - rules observed: 920420, 949110, 980170
- CVE-2024-32113 - Apache OFBiz Directory Traversal - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2024-32640 - Mura/Masa CMS - SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2024-39907 - 1Panel SQL Injection - Authenticated - rules observed: 380026
- CVE-2024-4358 - Progress Telerik Report Server - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2024-48307 - JeecgBoot v3.7.1 - SQL Injection - rules observed: 340159
- CVE-2024-50498 - WP Query Console <= 1.0 - Remote Code Execution - rules observed: 340095
- CVE-2024-5084 - Hash Form <= 1.1.0 - Arbitrary File Upload - rules observed: 920420, 949110, 980170
- CVE-2024-57045 - D-Link DIR-859 - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2024-5827 - Vanna - SQL injection - rules observed: 344360
- CVE-2024-6220 - WordPress Keydatas ≤ 2.5.2 - Arbitrary File Upload - rules observed: 920420, 949110, 980170
- CVE-2024-6670 - WhatsUp Gold HasErrors SQL Injection - Authentication Bypass - rules observed: 340016
- CVE-2024-6671 - WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass - rules observed: 340016
- CVE-2025-30406 - Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE - rules observed: 920420, 949110, 980170
- CVE-2025-3248 - Langflow AI - Unauthenticated Remote Code Execution - rules observed: 344360
- CVE-2025-3605 - WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation - rules observed: 920420, 949110, 980170
- CVE-2025-4322 - Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover - rules observed: 920420, 949110, 980170
- CVE-2025-48827 - vBulletin 5.0.0-6.0.3 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2025-5394 - Unauthenticated Arbitrary Plugin Upload in Alone Theme - rules observed: 920420, 949110, 980170
- CVE-2026-0770 - Langflow < 1.3.0 - Remote Code Execution via validate_code() exec() - rules observed: 920420, 949110, 980170
- CVE-2026-1357 - WPvivid Backup & Migration <= 0.9.123 - Arbitrary File Upload - rules observed: 920420, 949110, 980170
- CVE-2026-35273 - Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE - rules observed: 920420, 949110, 980170
- CVE-2026-3844 - Breeze <= 2.4.4 - Arbitrary File Upload - rules observed: 920420, 949110, 980170
- CVE-2026-3891 - Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload - rules observed: 920420, 949110, 980170
- CVE-2026-48611 - phpBB < 3.3.17 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2026-8037 - Progress ADC LoadMaster - Command Injection - rules observed: 344360
- CVE-2026-9082 - Drupal Core - Anonymous SQL Injection via PostgreSQL Entity Query - rules observed: 340156
- CVE-2026-28496 - FOSSBilling - Server-Side Template Injection - rules observed: 340155
- CVE-2023-32590 - Subscribe to Category <= 2.7.4 - SQL Injection - rules observed: 380122
- CVE-2025-0868 - DocsGPT - Unauthenticated Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2025-25037 - Aquatronica Controller System <= 5.1.6 - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2025-26793 - FREEDOM Administration - Default Login - rules observed: 920420, 949110, 980170
- CVE-2026-3055 - Citrix NetScaler SAML IDP - Memory Overread - rules observed: 920420, 949110, 980170
- CVE-2026-54836 - YMC Filter - SQL Injection - rules observed: 380122
- CVE-2019-17574 - Popup-Maker < 1.8.12 - Broken Authentication - rules observed: 920420, 949110, 980170
- CVE-2019-9880 - WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosure - rules observed: 344361
- CVE-2020-25762 - Seat Reservation System 1.0 - Unauthenticated SQL Injection - rules observed: 920420, 932235, 932260, 949110, 980170
- CVE-2021-37425 - Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE) - rules observed: 330791
- CVE-2021-46424 - TLR-2005KSH - Arbitrary File Delete - rules observed: 911100, 949110, 980170
- CVE-2024-28987 - SolarWinds Web Help Desk - Hardcoded Credential - rules observed: 920420, 949110, 980170
- CVE-2024-5315
- Dolibarr ERP CMS
list.php- SQL Injection - rules observed: 920420, 949110, 980170 - CVE-2024-3300 - Delmia Apriso - Pre-Authentication Unsafe .NET Object Deserialization - rules observed: 920420, 949110, 980170
- CVE-2017-6823 - Fiyo CMS 2.0.6.1 - Privilege Escalation - rules observed: 920420, 949110, 980170
- CVE-2018-15142 - OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions - rules observed: 920420, 949110, 980170
- CVE-2019-11886 - Yellow Pencil Visual Theme Customizer < 7.2.1 - Privilege Escalation - rules observed: 920420, 949110, 980170
- CVE-2019-3398 - Atlassian Confluence Download Attachments - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2020-10199 - Sonatype Nexus Repository Manager 3 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2020-11978 - Apache Airflow <=1.10.10 - Remote Code Execution - rules observed: 344364
- CVE-2020-1956 - Apache Kylin 3.0.1 - Command Injection Vulnerability - rules observed: 920420, 949110, 980170
- CVE-2020-5192 - Hospital Management System 4.0 - ‘searchdata’ SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2021-34622 - WordPress ProfilePress <= 3.1.3 - Privilege Escalation - rules observed: 920420, 949110, 980170
- CVE-2022-0824 - Webmin <1.990 - Improper Access Control - rules observed: 920420, 949110, 980170
- CVE-2022-37190 - Cuppa CMS v1.0 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2023-22952 - SugarCRM Unauthenticated - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2023-25194 - Apache Druid Kafka Connect - Remote Code Execution - rules observed: 930120, 949110, 980170
- CVE-2023-32749 - Pydio Cells 4.1.2 - Unauthorised Role Assignments - rules observed: 330791, 911100, 980170
- CVE-2023-37270 - Piwigo 13.7.0 - SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2025-1097
- Ingress-Nginx Controller - Configuration Injection via Unsanitized
auth-tls-match-cnAnnotation - rules observed: 942100, 949110, 980170 - CVE-2025-51482 - Letta Letta 0.7.12 - Remote Code Execution - rules observed: 933160, 942151, 949110, 980170
- CVE-2026-35029 - LiteLLM - Arbitrary File Read - rules observed: 344360
- CVE-2026-5027 - Langflow <= 1.8.4 - Path Traversal to RCE via File Upload - rules observed: 920420, 949110, 980170
- CVE-2022-41800 - F5 BIG-IP Appliance Mode - Command Injection - rules observed: 344362
- CVE-2025-53558 - ZTE ZXHN-F660T/F660A - Default Credentials - rules observed: 920420, 949110, 980170
- CVE-2021-22175 - GitLab CI Lint API - Server-Side Request Forgery - rules observed: 344362
- CVE-2021-22214 - Gitlab CE/EE 10.5 - Server-Side Request Forgery - rules observed: 344362
- CVE-2022-1026 - Kyocera Net View Address Book Exposure - rules observed: 920420, 949110, 980170
- CVE-2023-47211 - ManageEngine OpManager - Directory Traversal - rules observed: 920420, 949110, 980170
- CVE-2024-4325 - Gradio - Server-Side Request Forgery - rules observed: 930120, 931100, 934110, 949110, 980170
- CVE-2023-40000 - LiteSpeed Cache <= 5.7 - Unauthenticated Stored XSS - rules observed: 920420, 949110, 980170
- CVE-2024-21683 - Atlassian Confluence Data Center and Server - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2024-35219 - OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete - rules observed: 340007
- CVE-2024-9465 - Palo Alto Expedition - SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2025-49002 - DataEase - Remote Code Execution - rules observed: 340195
- CVE-2016-4437 - Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability - rules observed: 920420, 949110, 980170
- CVE-2021-24647 - Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login - rules observed: 920420, 949110, 980170
- CVE-2022-1903 - ARMember < 3.4.8 - Unauthenticated Admin Account Takeover - rules observed: 920420, 949110, 980170
- CVE-2024-10783 - WordPress Plugin MainWP Child - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2018-12710 - DLink DIR-601 - Credential Disclosure - rules observed: 920420, 949110, 980170
- CVE-2018-5708 - DLink DIR-601 - Admin Password Disclosure - rules observed: 920420, 949110, 980170
- CVE-2025-2610 - MagnusBilling Alarm Module - Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2014-7226 - Rejetto HTTP File Server (HFS) 2.3a/2.3b/2.3c - Remote Command Execution - rules observed: 920250, 920420, 949110, 980170
- CVE-2017-14335 - Hanbanggaoke IP Camera - Arbitrary Password Change - rules observed: 911100, 920420, 930120, 941100, 949110, 980170
- CVE-2018-7171 - TwonkyMedia Server 7.0.11-8.5 - Directory Traversal - rules observed: 920420, 930100, 930110, 949110, 980170
- CVE-2019-16758 - Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal - rules observed: 920440, 980170
- CVE-2020-13405 - Microweber <1.1.20 - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2020-9376 - D-Link DIR-610 Devices - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2020-9483 - SkyWalking SQLI - rules observed: 341250
- CVE-2021-24278 - WordPress Contact Form 7 <2.3.4 - Arbitrary Nonce Generation - rules observed: 920420, 949110, 980170
- CVE-2021-37589 - Virtua Software Cobranca <12R - Blind SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2021-38146 - Wipro Holmes Orchestrator 20.4.1 - Arbitrary File Download - rules observed: 930120, 949110, 980170
- CVE-2021-38154 - Canon Devices - Authentication Bypass in Catwalk Server - rules observed: 920420, 949110, 980170
- CVE-2021-40655 - D-Link DIR-605 - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2021-46418 - Telesquare TLR-2855KS6 - Arbitrary File Creation - rules observed: 911100, 920420, 949110, 980170
- CVE-2022-0660 - Microweber <1.2.11 - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2022-21661 - WordPress <5.8.3 - SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2022-36923 - Zoho ManageEngine - getUserAPIKey Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2022-42953 - ZKTeco ZEM/ZMM 8.88 - Missing Authentication - rules observed: 920420, 949110, 980170
- CVE-2023-22620 - SecurePoint UTM 12.x Session ID Leak - rules observed: 943120, 949110, 980170
- CVE-2023-2356 - Mlflow <2.3.0 - Local File Inclusion - rules observed: 340007
- CVE-2023-25573 - Metersphere - Arbitrary File Read - rules observed: 930120, 932160, 949110, 980170
- CVE-2023-28432 - MinIO Cluster Deployment - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2023-31478 - GL.iNET SSID Key Disclosure - rules observed: 920420, 949110, 980170
- CVE-2023-34105 - SRS - Command Injection - rules observed: 344364
- CVE-2023-50968 - Apache OFBiz < 18.12.11 - Server Side Request Forgery - rules observed: 920420, 949110, 980170
- CVE-2024-0305 - Ncast busiFacade - Remote Command Execution - rules observed: 920420, 949110, 980170
- CVE-2024-1483 - Mlflow < 2.9.2 - Path Traversal - rules observed: 340007
- CVE-2024-1561 - Gradio 4.3-4.12 - Local File Read - rules observed: 344365, 930120, 932160, 949110, 980170
- CVE-2024-1728 - Gradio > 4.19.1 UploadButton - Path Traversal - rules observed: 344360
- CVE-2024-29198 - GeoServer Demo Request Endpoint - Server Side Request Forgery - rules observed: 920420, 949110, 980170
- CVE-2024-2928 - MLflow < 2.11.3 - Path Traversal - rules observed: 340007
- CVE-2024-36420 - Flowise 1.4.3 - Arbitrary File Read - rules observed: 344360
- CVE-2024-3848 - Mlflow < 2.11.0 - Path Traversal - rules observed: 340007
- CVE-2024-45195 - Apache OFBiz - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2024-48455 - Netis Wifi Router - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2024-6587 - LiteLLM - Server-Side Request Forgery - rules observed: 340162
- CVE-2025-1361 - IP2Location Country Blocker < 2.38.9 - Unauthenticated Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2025-2221 - WordPress WPCOM Member <= 1.7.6 - SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2025-24786 - WhoDB < 0.45.0 - Path Traversal - rules observed: 930110, 930120, 949110, 980170
- CVE-2025-27817 - Apache Kafka Client - Arbitrary File Read - rules observed: 344360
- CVE-2025-55184 - React Server Components - Denial of Service - rules observed: 920420, 949110, 980170
- CVE-2025-62039 - AI ChatBot with ChatGPT by AYS <= 2.6.6 - Unauthenticated API Key Exposure - rules observed: 920420, 949110, 980170
- CVE-2021-4448 - Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization - rules observed: 920420, 949110, 980170
- CVE-2024-46507 - Yeti Platform < 2.1.12 - Server-Side Template Injection to RCE - rules observed: 340130
- CVE-2025-56132 - LiquidFiles < 4.2 - User Enumeration via Password Reset - rules observed: 920420, 949110, 980170
- CVE-2021-21311 - Adminer <4.7.9 - Server-Side Request Forgery - rules observed: 920420, 949110, 980170
- CVE-2021-37292 - KevinLAB BEMS (Building Energy Management System) - Backdoor Account - rules observed: 920420, 949110, 980170
- CVE-2023-29084 - ManageEngine ADManager Plus - Command Injection - rules observed: 920420, 949110, 980170
- CVE-2023-39121 - Emlog 2.1.9 - SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2023-46818 - ISPConfig - PHP Code Injection - rules observed: 920420, 949110, 980170
- CVE-2024-38288 - TurboMeeting - Post-Authentication Command Injection - rules observed: 920420, 949110, 980170
- CVE-2026-49069 - WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS) - rules observed: 920420, 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2024-51228 - TOTOLINK CX-A3002RU - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2024-6886 - Gitea 1.22.0 - Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2018-1042 - Moodle Filepicker 3.5.2 - Server Side Request Forgery - rules observed: 920420, 949110, 980170
- CVE-2018-7691 - Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2) - rules observed: 330791
- CVE-2019-19743 - D-Link DIR-615 - Privilege Escalation - rules observed: 920420, 949110, 980170
- CVE-2020-13945 - Apache APISIX - Insufficiently Protected Credentials - rules observed: 380026
- CVE-2021-22145 - Elasticsearch 7.10.0-7.13.3 - Information Disclosure - rules observed: 330791
- CVE-2021-36749 - Apache Druid - Local File Inclusion - rules observed: 344360
- CVE-2022-37191 - Cuppa CMS v1.0 - Authenticated Local File Inclusion - rules observed: 920420, 949110, 980170
- CVE-2023-27167 - Suprema BioStar 2 v2.8.16 - SQL Injection - rules observed: 330791
- CVE-2023-32750 - Pydio Cells 4.1.2 - Server-Side Request Forgery - rules observed: 911100, 949110, 980170
- CVE-2024-24565 - CrateDB Database - Arbitrary File Read - rules observed: 340016, 344360
- CVE-2024-29272 - VvvebJs < 1.7.5 - Arbitrary File Upload - rules observed: 920420, 949110, 980170
- CVE-2024-33832 - OneNav v0.9.35-20240318 - Server-Side Request Forgery (SSRF) - rules observed: 920420, 949110, 980170
- CVE-2025-49706 - Microsoft SharePoint Server - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2026-39352 - Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversal - rules observed: 920420, 949110, 980170
- CVE-2024-32231 - Stash < 0.26.0 - SQL Injection - rules observed: 340016
- CVE-2025-13920 - WP Directory Kit < 1.5.0 - Unauthenticated Email Exposure - rules observed: 920420, 949110, 980170
- CVE-2016-10368 - Opsview Monitor Pro - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2017-11586 - FineCMS <5.0.9 - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2017-12138 - XOOPS Core 2.5.8 - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2018-20367 - WSTMart 2.0.8 - Cross-Site Scripting - rules observed: 920420, 920600, 941100, 941120, 941160, 941390, 949110, 980170
- CVE-2019-14223 - Alfresco Share - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2019-16931 - WordPress Visualizer <3.3.1 - Cross-Site Scripting - rules observed: 340147
- CVE-2019-9554 - Craft CMS 3.1.12 Pro - Cross-Site Scripting - rules observed: 920420, 941160, 941390, 942550, 949110, 980170
- CVE-2019-9915 - GetSimple CMS 3.3.13 - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2020-12704 - UliCMS 2020.1 - Persistent Cross-Site Scripting - rules observed: 920420, 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2020-12707 - LeptonCMS 4.5.0 - Persistent Cross-Site Scripting - rules observed: 920420, 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2020-23814 - XXL-JOB v2.2.0 — Stored Cross Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2020-24912 - QCube Cross-Site-Scripting - rules observed: 920420, 949110, 980170
- CVE-2020-8549 - WordPress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting - rules observed: 920420, 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2021-20323 - Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting - rules observed: 333141
- CVE-2021-27695 - openMAINT openMAINT 2.1-3.3-b - ‘Multiple’ Persistent Cross-Site Scripting - rules observed: 330791, 911100, 949110, 980170
- CVE-2021-33829 - Drupal 7 CKEditor XSS - rules observed: 920420, 949110, 980170
- CVE-2023-22432 - Web2py URL - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2023-41642 - RealGimm by GruppoSCAI v1.1.37p38 - Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2023-5914 - Citrix StoreFront - Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2024-28623 - RiteCMS 3.0.0 - Cross-site Scripting - rules observed: 920420, 949110, 980170
- CVE-2025-4123 - Grafana 11.6.0 - SSRF - rules observed: 930100, 949110, 980170
- CVE-2025-51501 - Microweber CMS2.0 - Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2025-51502 - Microweber CMS 2.0 - Reflected XSS in Admin Page Creation - rules observed: 920420, 949110, 980170
- CVE-2017-8295 - WordPress Core < 4.7.4 - Unauthorized Password Reset - rules observed: 920420, 949110, 980170
- CVE-2012-4032 - WebsitePanel before v1.2.2.1 - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2024-6095 - LocalAI - Partial Local File Read - rules observed: 344360
- CVE-2022-0968 - Microweber <1.2.12 - Integer Overflow - rules observed: 920420, 949110, 980170
- CVE-2017-6340 - Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities - rules observed: 920420, 932230, 932250, 942360, 949110, 980170
- CVE-2019-10226 - Fat Free CRM 0.19.0 - HTML Injection - rules observed: 920420, 949110, 980170
- CVE-2020-10385 - WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting - rules observed: 920420, 941100, 941110, 941160, 941390, 942550, 949110, 980170
- CVE-2020-11110 - Grafana <= 6.7.1 - Cross-Site Scripting - rules observed: 350148
- CVE-2020-15038 - Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting - rules observed: 920420, 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2020-23697 - Monstra CMS 3.0.4 - Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2020-29233 - WonderCMS 3.1.3 - ‘content’ Persistent Cross-Site Scripting - rules observed: 920420, 941100, 941120, 941160, 941390, 949110, 980170
- CVE-2022-0963 - Microweber <1.2.12 - Stored Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2022-30073 - WBCE CMS 1.5.2 - Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2023-27292 - OpenCATS - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2024-41819 - NoteMark < 0.13.0 - Stored XSS - rules observed: 911100, 949110, 980170
- CVE-2019-13383 - CentOS Control Web Panel 0.9.8.838 - User Enumeration - rules observed: 920420, 949110, 980170
- CVE-2019-17230 - WordPress OneTone theme <= 3.0.6 – Unauthenticated Options Changes - rules observed: 920420, 949110, 980170
- CVE-2019-1898 - Cisco RV110W RV130W RV215W Router - Information leakage - rules observed: 920420, 949110, 980170
- CVE-2020-26413 - Gitlab CE/EE 13.4 - 13.6.2 - Information Disclosure - rules observed: 932235, 949110, 980170
- CVE-2020-28185 - TerraMaster TOS < 4.2.06 - User Enumeration - rules observed: 920420, 949110, 980170
- CVE-2020-6308 - SAP BusinessObjects Business Intelligence Platform - Blind Server-Side Request Forgery - rules observed: 920420, 949110, 980170
- CVE-2020-6862 - ZTE Router F602W - Captcha Bypass - rules observed: 920420, 949110, 980170
- CVE-2021-24219 - All Thrive Themes and Plugins - Unauthenticated Option Update - rules observed: 920420, 949110, 980170
- CVE-2021-26085 - Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read - rules observed: 930130, 949110, 980170
- CVE-2021-28164 - Jetty 9.4.37.v20210219 - Information Disclosure - rules observed: 930130, 949110, 980170
- CVE-2021-4191 - GitLab GraphQL API User Enumeration - rules observed: 344361
- CVE-2022-0140 - WordPress Visual Form Builder <3.0.8 - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2022-0424 - Popup by Supsystic < 1.10.9 - Subscriber Email Addresses Disclosure - rules observed: 920420, 949110, 980170
- CVE-2022-2461 - Transposh WordPress Translation <= 1.0.8 - Unauthenticated Settings Change - rules observed: 920420, 949110, 980170
- CVE-2022-2462 - WordPress Transposh <=1.0.8.1 - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2022-25497 - Cuppa CMS v1.0 - Local File Inclusion - rules observed: 344360
- CVE-2022-28987 - Zoho ManageEngine ADSelfService Plus 6121 - Username Enumeration - rules observed: 920420, 949110, 980170
- CVE-2022-39960 - Jira Netic Group Export <1.0.3 - Missing Authorization - rules observed: 920420, 949110, 980170
- CVE-2023-1263 - Coming Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page Access - rules observed: 920420, 949110, 980170
- CVE-2023-6421 - WordPress Download Manager - File Password Exposure - rules observed: 920420, 949110, 980170
- CVE-2024-0235 - EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure - rules observed: 920420, 949110, 980170
- CVE-2024-0593 - WordPress Simple Job Board - Unauthorized Data Access - rules observed: 920420, 949110, 980170
- CVE-2024-1380 - Relevanssi (A Better Search) <= 4.22.0 - Query Log Export - rules observed: 920420, 949110, 980170
- CVE-2024-44762 - Usermin 2.100 - Username Enumeration - rules observed: 920420, 949110, 980170
- CVE-2025-11368 - LearnPress < 4.3.0 - Arbitrary Callback Execution to Information Exposure - rules observed: 344365
- CVE-2025-47813 - Wing FTP Server <= 7.4.3 - Path Disclosure via Overlong UID Cookie - rules observed: 920420, 949110, 980170
- CVE-2025-59136 - WordPress Gerencianet Oficial <= 3.1.3 - Unauthenticated Order Status Disclosure - rules observed: 920420, 949110, 980170
- CVE-2025-62126 - WordPress Varnish/Nginx Proxy Caching <= 1.8.3 - Information Exposure - rules observed: 920420, 949110, 980170
- CVE-2026-32583 - Webnus Inc. Modern Events Calendar - Broken Access Control - rules observed: 920420, 949110, 980170
- CVE-2024-41955 - Open Redirect in Login Redirect - MobSF - rules observed: 920420, 949110, 980170
- CVE-2020-29475 - nopCommerce Store 4.30 - ’name’ Stored Cross-Site Scripting - rules observed: 920420, 941100, 941120, 941160, 941390, 949110, 980170
- CVE-2024-50857 - GestioIP - Reflected Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2024-53995 - SickChill - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2012-0782 - WordPress Core 3.3.1 - Multiple Vulnerabilities - rules observed: 920420, 930130, 949110, 980170
- CVE-2022-3481 - NotificationX Dropshipping < 4.4 - SQL Injection - rules observed: 380122
- CVE-2023-45038 - QNAP Music Station < 5.4.0 - Authentication Bypass - rules observed: 920420, 949110, 980170
- CVE-2024-24763 - JumpServer < 3.10.0 - Open Redirect - rules observed: 920420, 949110, 980170
- CVE-2024-3378 - iboss Secure Web Gateway - Stored Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2024-39887 - Apache Superset < 4.0.2 - SQL Injection - rules observed: 942151, 949110, 980170
- CVE-2026-33534 - EspoCRM <= 9.3.3 - Server-Side Request Forgery - rules observed: 931100, 934110, 949110, 980170
- CVE-2019-8962 - FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin) - rules observed: 920420, 949110, 980170
- CVE-2024-24497 - Employee Management System 1.0 - txtusername and txtpassword SQL Injection (Admin Login) - rules observed: 920420, 949110, 980170
- CVE-2024-24499 - Employee Management System 1.0 - txtfullname and txtphone SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2026-11111 - Research note for exploit techniques associated with CVE-2026-11111 - rules observed: 340016, 340162
- CVE-2026-48907 - Research note for exploit techniques associated with CVE-2026-48907 - rules observed: 383871, 333360
- CVE-2026-60137 - Pre-existing generic rules block the WordPress author__not_in SQL injection - rules observed: 340156, 344370
- CVE-2026-63030 - Pre-existing generic rules disrupt the WordPress route-confusion SQL injection chain - rules observed: 340156, 344370