Atomicorp WAF Research Notes

Research Update - 2026-08-10

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2017-16949Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload345493
CVE-2017-7402Pixie 1.0.4 - Arbitrary File Upload345493
CVE-2022-1040Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass345493
CVE-2022-31188CVAT 2.0 - Server Side Request Forgery345493
CVE-2019-15813Sentrifugo 3.2 - File Upload Restriction Bypass345493
CVE-2020-35151Online Marriage Registration System 1.0 - 'searchdata' SQL Injection345493
CVE-2020-8639TestLink 1.9.20 - Unrestricted File Upload (Authenticated)345493
CVE-2021-46398FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)345490 , 345493
CVE-2022-25241FileCloud 21.2 - Cross-Site Request Forgery (CSRF)345490
CVE-2023-0916Auto Dealer Management System 1.0 - Broken Access Control Exploit345493
CVE-2017-14335Hanbanggaoke IP Camera - Arbitrary Password Change345493
CVE-2022-21661WordPress Core 5.8.2 - 'WP_Query' SQL Injection345493
CVE-2022-42953ZKTeco ZEM/ZMM 8.88 - Missing Authentication345493
CVE-2019-19743D-Link DIR-615 - Privilege Escalation345493
CVE-2019-8394Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload345493
CVE-2018-18308BigTree CMS 4.2.23 - Cross-Site Scripting345493
CVE-2018-20367WSTMart 2.0.8 - Cross-Site Scripting345493
CVE-2019-11846dotCMS 5.1.1 - HTML Injection345493
CVE-2020-12707LeptonCMS 4.5.0 - Persistent Cross-Site Scripting345493
CVE-2024-36599AEGON LIFE v1.0 Life Insurance Management System - Stored cross-site scripting (XSS)345493
CVE-2019-17554Apache Olingo OData 4.0 - XML External Entity Injection344372 , 345493
CVE-2023-46018Blood Bank v1.0 - Multiple SQL Injection345493
CVE-2020-15038Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting345493
CVE-2020-29233WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting345493
CVE-2023-3187Teachers Record Management System 1.0 - File Upload Type Validation345493
CVE-2023-3184Sales Tracker Management System v1.0 - Multiple Vulnerabilities345493
CVE-2019-8962FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)345490