Atomicorp WAF Research Notes
Research Update - 2026-08-10
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2017-16949 | Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload | 345493 |
| CVE-2017-7402 | Pixie 1.0.4 - Arbitrary File Upload | 345493 |
| CVE-2022-1040 | Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass | 345493 |
| CVE-2022-31188 | CVAT 2.0 - Server Side Request Forgery | 345493 |
| CVE-2019-15813 | Sentrifugo 3.2 - File Upload Restriction Bypass | 345493 |
| CVE-2020-35151 | Online Marriage Registration System 1.0 - 'searchdata' SQL Injection | 345493 |
| CVE-2020-8639 | TestLink 1.9.20 - Unrestricted File Upload (Authenticated) | 345493 |
| CVE-2021-46398 | FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE) | 345490 , 345493 |
| CVE-2022-25241 | FileCloud 21.2 - Cross-Site Request Forgery (CSRF) | 345490 |
| CVE-2023-0916 | Auto Dealer Management System 1.0 - Broken Access Control Exploit | 345493 |
| CVE-2017-14335 | Hanbanggaoke IP Camera - Arbitrary Password Change | 345493 |
| CVE-2022-21661 | WordPress Core 5.8.2 - 'WP_Query' SQL Injection | 345493 |
| CVE-2022-42953 | ZKTeco ZEM/ZMM 8.88 - Missing Authentication | 345493 |
| CVE-2019-19743 | D-Link DIR-615 - Privilege Escalation | 345493 |
| CVE-2019-8394 | Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload | 345493 |
| CVE-2018-18308 | BigTree CMS 4.2.23 - Cross-Site Scripting | 345493 |
| CVE-2018-20367 | WSTMart 2.0.8 - Cross-Site Scripting | 345493 |
| CVE-2019-11846 | dotCMS 5.1.1 - HTML Injection | 345493 |
| CVE-2020-12707 | LeptonCMS 4.5.0 - Persistent Cross-Site Scripting | 345493 |
| CVE-2024-36599 | AEGON LIFE v1.0 Life Insurance Management System - Stored cross-site scripting (XSS) | 345493 |
| CVE-2019-17554 | Apache Olingo OData 4.0 - XML External Entity Injection | 344372 , 345493 |
| CVE-2023-46018 | Blood Bank v1.0 - Multiple SQL Injection | 345493 |
| CVE-2020-15038 | Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting | 345493 |
| CVE-2020-29233 | WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting | 345493 |
| CVE-2023-3187 | Teachers Record Management System 1.0 - File Upload Type Validation | 345493 |
| CVE-2023-3184 | Sales Tracker Management System v1.0 - Multiple Vulnerabilities | 345493 |
| CVE-2019-8962 | FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin) | 345490 |