Deep Security Center

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Directory Server LDAP
1012309 - OpenLDAP SQL Injection Vulnerability (CVE-2022-29155)


Ivanti Endpoint Manager
1012149* - Ivanti Endpoint Manager Multiple SQL Injection Vulnerabilities - 1
1012253* - Ivanti Endpoint Manager SQL Injection Vulnerability (CVE-2024-32848)
1012283 - Ivanti Endpoint Manager Untrusted Search Path Vulnerability (CVE-2024-13158)


SolarWinds Orion Platform
1012316 - SolarWinds Orion Platform Server-Side Request Forgery Vulnerability (CVE-2024-52606)


Web Application PHP Based
1012308 - WordPress 'Hunk Companion' Plugin Broken Access Control Vulnerability (CVE-2024-11972)
1012313 - WordPress 'Ultimate Exporter' Plugin Command Injection Vulnerability (CVE-2024-56278)


Web Client HTTPS
1012220 - Ivanti Endpoint Manager Multiple Directory Traversal Vulnerabilities


Web Server HTTPS
1012292 - Zabbix SQL Injection Vulnerability (CVE-2024-42327)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

CyberPanel
1012300 - CyberPanel Command Injection Vulnerability (CVE-2024-51378)


HPE Insight Remote Support
1012304 - HPE Insight Remote Support Directory Traversal Vulnerability (CVE-2024-53676)


OpenSSL
1012310 - OpenSSL Denial of Service Vulnerability (CVE-2024-6119) - Server


OpenSSL Client
1012311 - OpenSSL Denial of Service Vulnerability (CVE-2024-6119) - Client


Web Application Common
1012290 - Pandora FMS Command Injection Vulnerability (CVE-2024-11320)


Web Application PHP Based
1012279 - WordPress 'WP Time Capsule' Plugin Arbitrary File Upload Vulnerability (CVE-2024-8856)


Web Proxy Squid
1012273* - Squid Proxy Denial Of Service Vulnerability (CVE-2024-45802)


Web Server Apache
1012305 - Chamilo Command Injection Vulnerabilities (CVE-2023-34960 and CVE-2023-3368)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Ivanti Avalanche
1012296 - Ivanti Avalanche Path Traversal Vulnerability (CVE-2024-13179)


Ivanti Endpoint Manager
1012271* - Ivanti Endpoint Manager Multiple Denial Of Service Vulnerabilities
1012278 - Ivanti Endpoint Manager Multiple Denial Of Service Vulnerabilities (CVE-2024-13170 and CVE-2024-13167)
1012253 - Ivanti Endpoint Manager SQL Injection Vulnerability (CVE-2024-32848)


JetBrains TeamCity
1012297 - JetBrains TeamCity Cross-Site Scripting Vulnerability (CVE-2025-24459)


Solr Service
1012291* - Apache Solr Directory Traversal Vulnerability (CVE-2024-52012)


Web Application PHP Based
1012097* - LibreNMS SQL Injection Vulnerability (CVE-2024-32461)
1012301 - WordPress 'Quiz Maker' Plugin Reflected Cross-Site Scripting Vulnerability (CVE-2023-2571)
1012226 - WordPress 'wpForo' Plugin Local File Inclusion Vulnerability (CVE-2023-2249)


Web Client Common
1008828* - Speculative Execution Information Disclosure Vulnerabilities (Spectre)


Web Server HTTPS
1012284 - Apache Traffic Control SQL Injection Vulnerability (CVE-2024-45387)


Web Server Miscellaneous
1012303 - XWiki Code Injection Vulnerability (CVE-2025-24893)


Windows Server DCERPC
1012209* - Microsoft Windows Remote Desktop Licensing Service Denial of Service Vulnerability (CVE-2024-38071)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Ivanti Avalanche
1012298 - Ivanti Avalanche Authentication Bypass Vulnerability (CVE-2024-13181)


Ivanti Endpoint Manager
1012271 - Ivanti Endpoint Manager Multiple Denial Of Service Vulnerabilities


Solr Service
1012280 - Apache Solr Authentication Bypass Vulnerability (CVE-2024-45216)
1012291 - Apache Solr Directory Traversal Vulnerability (CVE-2025-52012)


Web Client Common
1012282* - Microsoft Windows Themes Spoofing Vulnerability (CVE-2025-21308)


Integrity Monitoring Rules:

1012288 - Vulnerability - Microsoft Windows Active Directory Elevation of Privilege (CVE-2025-21293) (ATT&CK T1112, T1546.003, T1574.011)


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Directory Client LDAP TCP
1012276 - Microsoft Windows LDAP Integer Overflow Vulnerability (CVE-2024-49112)


Microsoft Configuration Manager
1012289 - Microsoft Configuration Manager SQL Injection Vulnerability (CVE-2024-43468)


Progress WhatsUp Gold
1012287 - Progress WhatsUp Gold Directory Traversal Vulnerability (CVE-2024-12105)


Web Application PHP Based
1012265 - WordPress 'White Label MS' Plugin Reflected Cross-Site Scripting Vulnerability (CVE-2022-0422)


Web Client Common
1012282 - Microsoft Windows Themes Spoofing Vulnerability (CVE-2025-21308)


Web Server Miscellaneous
1012248 - Jenkins 'Simple Queue' Plugin Stored Cross-Site Scripting Vulnerability (CVE-2024-54003)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

MyQ Print Server
1012268 - MyQ Print Server Remote Code Execution Vulnerability (CVE-2024-28059)


Progress WhatsUp Gold
1012237 - Progress WhatsUp Gold SQL Injection Vulnerability (CVE-2024-46905)


Trend Micro Common
1012272 - Trend Micro Multiple Products Path Traversal Vulnerabilities


Web Application PHP Based
1011999* - BoidCMS Command Injection Vulnerability (CVE-2023-38836)
1012021* - Grav CMS Directory Traversal Vulnerability (CVE-2024-27921)
1012073* - LibreNMS Cross-Site Scripting Vulnerability (CVE-2024-32479)
1011993* - LibreNMS SQL Injection Vulnerability (CVE-2023-5591)
1012260 - LibreNMS Stored Cross-Site Scripting Vulnerability (CVE-2024-50352)
1012277 - LibreNMS Stored Cross-Site Scripting Vulnerability (CVE-2024-53457)
1011975* - WordPress 'Backup Migration' Plugin Command Injection Vulnerability (CVE-2023-7002)
1012067* - WordPress 'Forminator' Plugin SQL Injection Vulnerability (CVE-2024-31077)
1012014* - WordPress 'LayerSlider' Plugin SQL Injection Vulnerability (CVE-2024-2879)
1011968* - WordPress 'LearnPress' Plugin SQL Injection Vulnerability (CVE-2023-6567)
1012005* - WordPress 'Popup Builder' Plugin Cross-Site Scripting Vulnerability (CVE-2023-6000)
1012007* - WordPress 'Ultimate Member' Plugin SQL Injection Vulnerability (CVE-2024-1071)
1012045* - WordPress 'WPvivid Backup' Plugin Insecure Deserialization Vulnerability (CVE-2024-3054)


Web Application Tomcat
1012274 - Apache Tomcat Race Condition Vulnerability (CVE-2024-50379 and CVE-2024-56337)


Web Server HTTPS
1012255 - GFI Archiver Telerik Web UI Remote Code Execution Vulnerability (CVE-2024-11948)
1012051* - WordPress Core Cross-Site Scripting Vulnerability (CVE-2024-4439)


Web Server Miscellaneous
1011948* - Ivanti Avalanche Multiple Remote Code Execution Vulnerabilities


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

OneDev Server
1012270 - OneDev Arbitrary File Read Vulnerability (CVE-2024-45309)


SNMP Client
1012269 - Paessler PRTG Network Monitor Cross-Site Scripting Vulnerability (CVE-2024-12833)


Web Application Tomcat
1012251 - LibreNMS Command Injection Vulnerability (CVE-2024-51092)


Web Proxy Squid
1012273 - Squid Proxy Denial Of Service Vulnerability (CVE-2024-45802)


Web Server HTTPS
1012264 - Veritas Enterprise Vault Cross-Site Scripting Vulnerabilities (CVE-2024-52941) and (CVE-2024-52942)
1012262 - Veritas Enterprise Vault Cross-Site Scripting Vulnerability (CVE-2024-52943)
1012266 - Veritas Enterprise Vault Cross-Site Scripting Vulnerability (CVE-2024-52944)


Web Server Miscellaneous
1012258 - XWiki Information Disclosure Vulnerability (CVE-2023-50719)


Web Server Nagios
1012275 - Nagios XI 'windows-winrm.inc.php' Command Injection Vulnerability


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Ivanti Endpoint Manager
1012149* - Ivanti Endpoint Manager Multiple SQL Injection Vulnerabilities - 1
1012205* - Ivanti Endpoint Manager SQL Injection Vulnerability (CVE-2024-50326)


WSO2
1012249 - WSO2 Multiple Products Arbitrary File Upload Vulnerability (CVE-2024-7074)


Web Application PHP Based
1012243 - MediaWiki CSS Extension Path Traversal Vulnerability (CVE-2024-47841)
1012261 - WordPress 'Drag and Drop Multiple File Upload - Contact Form 7' Plugin Stored Cross-Site Scripting Vulnerability (CVE-2022-0595)
1012259 - WordPress 'VR Calendar' Plugin Command Injection Vulnerability (CVE-2022-2314)
1012257 - WordPress 'Watu Quiz' Plugin Cross-Site Scripting Vulnerability (CVE-2023-0968)


Web Server HTTPS
1012241 - Cacti Stored Cross-Site Scripting Vulnerabilities (CVE-2024-43364 and CVE-2024-43365)
1012267 - WordPress 'NotificationX' Plugin SQL Injection Vulnerability (CVE-2022-0349)
1012223 - WordPress Core Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2024-31210)


Windows Server DCERPC
1012246 - Microsoft Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability (CVE-2024-38073)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

1002815* - Authentication Module - Unix Pluggable Authentication Module
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Ivanti Endpoint Manager
1012245 - Ivanti Endpoint Manager SQL Injection Vulnerability (CVE-2024-34783)


Progress WhatsUp Gold WCF service
1012117* - Progress WhatsUp Gold Directory Traversal Vulnerability (CVE-2024-4883 & CVE-2024-46909)


Veritas Enterprise Vault
1012229* - Veritas Enterprise Vault Remote Code Execution Multiple Vulnerabilities


Web Application PHP Based
1012247 - WordPress 'Super Backup & Clone' Plugin Arbitrary File Upload Vulnerability (CVE-2024-9290)


Webmin
1012254 - Webmin Remote Code Execution Vulnerability (CVE-2024-12828)


Zoho ManageEngine
1012250 - Zoho ManageEngine Analytics Plus Privilege Escalation Vulnerability (CVE-2024-52323)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Ivanti Avalanche Remote Control Server
1012176* - Ivanti Avalanche Server-Side Request Forgery Vulnerability (CVE-2024-47008)


Ivanti Endpoint Manager
1012205 - Ivanti Endpoint Manager SQL Injection Vulnerability (CVE-2024-50326)
1012207 - Ivanti Endpoint Manager SQL Injection Vulnerability (CVE-2024-50330)


Mail Server Common
1012185* - Roundcube Webmail Information Disclosure Vulnerability (CVE-2024-42010)


Progress WhatsUp Gold
1012242 - Progress WhatsUp Gold SQL Injection Vulnerability (CVE-2024-46906)


Veritas Enterprise Vault
1012229 - Veritas Enterprise Vault Remote Code Execution Multiple Vulnerabilities


Web Server HTTPS
1012218* - Centreon SQL Injection Vulnerability (CVE-2024-39841)
1012197* - Centreon SQL Injection Vulnerability (CVE-2024-5725)
1012147 - GitLab Denial of Service Vulnerability (CVE-2023-6502)
1012066* - PHP-CGI Argument Injection Vulnerability (CVE-2024-4577)


Web Server Oracle
1012244 - Oracle WebLogic Server Insecure Deserialization Vulnerability (CVE-2024-21182)


Windows SMB Server
1012219* - Trend Micro Deep Security Agent Command Injection Vulnerability (CVE-2024-51503)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.