| DDI RULE 5847 | Langflow Code Injection RCE Exploit - HTTP (Request) | HIGH | | 2026/06/02 | DDI RULE 5847 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5847 |
| DDI RULE 5846 | CVE-2026-23921 - Zabbix API SQL Injection Exploit - HTTP(Request) | HIGH | | 2026/06/01 | DDI RULE 5846 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5846 |
| DDI RULE 5838 | CVE-2025-6978 - Artista NG Firewall Command Injection Exploit - HTTP(Request) | HIGH | | 2026/05/28 | DDI RULE 5838 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5838 |
| DDI RULE 5843 | CVE-2025-30208 - ViteJS Traversal Exploit - HTTP(Request) | HIGH | | 2026/05/28 | DDI RULE 5843 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5843 |
| DDI RULE 5844 | Apache RCE Exploit - HTTP(Request) | HIGH | | 2026/05/28 | DDI RULE 5844 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5844 |
| DDI RULE 5845 | CVE-2025-32813 - Inflobox RCE Exploit - HTTP(Request) | HIGH | | 2026/05/28 | DDI RULE 5845 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5845 |
| DDI RULE 5842 | CVE-2024-20439 - CISCO CSLU RCE EXPLOIT - HTTP(Response) | HIGH | | 2026/05/26 | DDI RULE 5842 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5842 |
| DDI RULE 5836 | CVE-2026-42945 - F5 NGINX Buffer Overflow Exploit - HTTP(Request) | HIGH | | 2026/05/26 | DDI RULE 5836 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5836 |
| DDI RULE 5837 | CVE-2026-3838 - Unraid Update and Authentication Request Path Traversal Exploit - HTTP (Request) | HIGH | | 2026/05/26 | DDI RULE 5837 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5837 |
| DDI RULE 5839 | CVE-2025-6979 - Artista NG Firewall Authentication Bypass Exploit - HTTP(Request) | HIGH | | 2026/05/26 | DDI RULE 5839 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5839 |
| DDI RULE 5840 | CVE-2025-6980 - Artista NG Firewall RCE Exploit - HTTP(Request) | HIGH | | 2026/05/26 | DDI RULE 5840 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5840 |
| DDI RULE 5841 | CVE-2026-20029 - Cisco ISE XXE Exploit - HTTP(Request) | HIGH | | 2026/05/26 | DDI RULE 5841 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5841 |
| DDI RULE 5829 | CVE-2026-20186 - UnrealIRCd RCE Exploit - TCP(Request) | HIGH | | 2026/05/25 | DDI RULE 5829 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5829 |
| DDI RULE 5832 | CVE-2020-24949 - PHPFusion RCE Exploit - HTTP(Request) | HIGH | | 2026/05/25 | DDI RULE 5832 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5832 |
| DDI RULE 5833 | CVE-2025-5777 - Citrix Buffer Exploit - HTTP(Request) | HIGH | | 2026/05/25 | DDI RULE 5833 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5833 |
| DDI RULE 5834 | CVE-2026-20186 - Cisco Traversal Exploit - HTTP(Request) | HIGH | | 2026/05/25 | DDI RULE 5834 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5834 |
| DDI RULE 5835 | CVE-2024-7029 - AVTech CMD Injection - HTTP(Request) | HIGH | | 2026/05/25 | DDI RULE 5835 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5835 |
| DDI RULE 5827 | CVE-2026-42897 - Microsoft Exchange Server OWA - HTTP (Response) | HIGH | | 2026/05/18 | DDI RULE 5827 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5827 |
| DDI RULE 5826 | CVE-2026-3342 - WatchGuard Fireware OS Stack Buffer Overflow Exploit - HTTP(Request) | HIGH | | 2026/05/18 | DDI RULE 5826 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5826 |
| DDI RULE 5823 | Oracle RCE Exploit - HTTP(Request) | HIGH | | 2026/05/18 | DDI RULE 5823 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5823 |
| DDI RULE 5824 | CVE-2025-27240 - Zabbix SQL Injection Exploit - HTTP(Request) | HIGH | | 2026/05/18 | DDI RULE 5824 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5824 |
| DDI RULE 5825 | CVE-2021-36260 - Hikvision CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/05/18 | DDI RULE 5825 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5825 |
| DDI RULE 5817 | REMUS STEALER - HTTP(Response) | HIGH | | 2026/05/18 | DDI RULE 5817 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5817 |
| DDI RULE 5822 | Microsoft Office LineServices Layout Engine RCE Exploit - SMTP (Request) | HIGH | | 2026/05/13 | DDI RULE 5822 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5822 |
| DDI RULE 5819 | CVE-2026-27876 - Grafana Labs Grafana SQL Expressions Exploit - HTTP(Request) | MEDIUM | | 2026/05/13 | DDI RULE 5819 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5819 |
| DDI RULE 5821 | Windows NetLogon Buffer Overflow Exploit - UDP (Request) | HIGH | | 2026/05/13 | DDI RULE 5821 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5821 |
| DDI RULE 5820 | CVE-2026-0300 - PAN OS Buffer Overflow Exploit - HTTP(Request) | HIGH | | 2026/05/12 | DDI RULE 5820 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5820 |
| DDI RULE 5818 | CVE-2026-20180 - Cisco Identity Services Engine Directory Traversal Exploit - HTTP(Request) | HIGH | | 2026/05/12 | DDI RULE 5818 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5818 |
| DDI RULE 5810 | CVE-2025-7769 - Tigo CMD Injection - HTTP(Request) | LOW | | 2026/05/12 | DDI RULE 5810 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5810 |
| DDI RULE 5811 | CVE-2026-0768 - LANGFLOW RCE EXPLOIT - HTTP(Request) | MEDIUM | | 2026/05/12 | DDI RULE 5811 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5811 |
| DDI RULE 5801 | SHULUD GitHub Repository Exfiltration - HTTP (Request) | HIGH | | 2026/05/12 | DDI RULE 5801 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5801 |
| DDI RULE 5802 | Bun Package GitHub Download Sensor - HTTP (Request) | HIGH | | 2026/05/12 | DDI RULE 5802 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5802 |
| DDI RULE 5803 | Exfiltration via Dead Drop C2 - HTTP (Response) | HIGH | | 2026/05/12 | DDI RULE 5803 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5803 |
| DDI RULE 5806 | CVE-2023-51833 - TrendNet CMD Injection Exploit - HTTP(Response) | HIGH | | 2026/05/12 | DDI RULE 5806 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5806 |
| DDI RULE 5816 | CVE-2025-15063 - OLLAMA MCP RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/05/11 | DDI RULE 5816 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5816 |
| DDI RULE 5794 | CVE-2018-1171 - TPLink CMD INJ Exploit - HTTP(Response) | HIGH | | 2026/05/11 | DDI RULE 5794 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5794 |
| DDI RULE 5808 | CVE-2026-25654 - Siemens SINEC NMS Privilege Escalation Exploit - HTTP (Request) | HIGH | | 2026/05/11 | DDI RULE 5808 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5808 |
| DDI RULE 5809 | Tenda Router CMD Injection - HTTP(Request) | HIGH | | 2026/05/11 | DDI RULE 5809 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5809 |
| DDI RULE 5812 | CVE-2026-0773 - UPSONIC RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/05/11 | DDI RULE 5812 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5812 |
| DDI RULE 5813 | CVE-2026-0757 - MCP Command Injection Exploit - HTTP(Response) | HIGH | | 2026/05/11 | DDI RULE 5813 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5813 |
| DDI RULE 5814 | CVE-2025-67685 - FORTINET SSRF RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/05/11 | DDI RULE 5814 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5814 |
| DDI RULE 5815 | CVE-2026-0763 - GPT ACADEMIC RCE EXPLOIT - HTTP(Request) | MEDIUM | | 2026/05/11 | DDI RULE 5815 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5815 |
| DDI RULE 5807 | CVE-2026-34197 - Apache RCE Exploit - HTTP(Request) | HIGH | | 2026/05/07 | DDI RULE 5807 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5807 |
| DDI RULE 5805 | CVE-2025-68614 - LibreNMS XSS Exploit - HTTP(Request) | HIGH | | 2026/05/06 | DDI RULE 5805 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5805 |
| DDI RULE 5797 | Belkin Edimax CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/05/06 | DDI RULE 5797 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5797 |
| DDI RULE 5804 | CVE-2025-40598 - SonicWall XSS Exploit - HTTP(Request) | HIGH | | 2026/05/06 | DDI RULE 5804 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5804 |
| DDI RULE 5798 | CVE-2026-0764 - GPT RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/05/05 | DDI RULE 5798 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5798 |
| DDI RULE 5786 | CVE-2025-15060 - Claude-Hovercraft executeClaudeCode RCE Exploit - HTTP (Request) | HIGH | | 2026/05/05 | DDI RULE 5786 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5786 |
| DDI RULE 5799 | CVE-2026-0762 - GPT RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/05/05 | DDI RULE 5799 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5799 |
| DDI RULE 5800 | CVE-2026-0774 - LAN RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/05/05 | DDI RULE 5800 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5800 |
| DDI RULE 1586 | Bitcoin Mining - TCP(Request) | HIGH | | 2026/05/04 | DDI RULE 1586 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-1586 |
| DDI RULE 5795 | CVE-2025-54353 - FORTINET XSS EXPLOIT - HTTP(Request) | HIGH | | 2026/05/04 | DDI RULE 5795 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5795 |
| DDI RULE 5796 | CVE-2026-2033 - MLFLOW TRAVERSAL EXPLOIT - HTTP(Request) | HIGH | | 2026/05/04 | DDI RULE 5796 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5796 |
| DDI RULE 5792 | cPanel and WHM Authentication Bypass Exploit - HTTP (Request) | HIGH | | 2026/04/30 | DDI RULE 5792 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5792 |
| DDI RULE 5791 | Access to a Resource or Site using Dynamic DNS Service - HTTPS (Request) | HIGH | | 2026/04/29 | DDI RULE 5791 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5791 |
| DDI RULE 5763 | Use or Access of Dynamic DNS Services - DNS (Response) | HIGH | | 2026/04/29 | DDI RULE 5763 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5763 |
| DDI RULE 5785 | CVE-2025-40536 - SolarWinds Web Help Desk checkCsrfTokenWo Authentication Bypass Exploit - HTTP(Response) | HIGH | | 2026/04/29 | DDI RULE 5785 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5785 |
| DDI RULE 5784 | CVE-2025-61812 - Adobe ColdFusion _storeCFSettingFile Directory Traversal Exploit - HTTP(Response) | HIGH | | 2026/04/28 | DDI RULE 5784 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5784 |
| DDI RULE 5787 | CVE-2026-2635 - MLflow Use of Default Password Authentication Bypass Exploit - HTTP(Request) | HIGH | | 2026/04/28 | DDI RULE 5787 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5787 |
| DDI RULE 5788 | CVE-2026-5491 - DriveLock Directory Traversal Exploit - HTTP (Request) | HIGH | | 2026/04/28 | DDI RULE 5788 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5788 |
| DDI RULE 5789 | CVE-2026-5490 - DriveLock SQL Injection Exploit - HTTP (Request) | HIGH | | 2026/04/28 | DDI RULE 5789 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5789 |
| DDI RULE 5790 | CVE-2026-5487 - DriveLock Directory Traversal Exploit - HTTP (Request) | HIGH | | 2026/04/28 | DDI RULE 5790 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5790 |
| DDI RULE 5781 | CVE-2025-66034 - FONTTOOLS XML EXPLOIT - HTTP(Request) | HIGH | | 2026/04/27 | DDI RULE 5781 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5781 |
| DDI RULE 5782 | CVE-2026-20079 - CISCO AUTHBYPASS EXPLOIT - HTTP(Request) | HIGH | | 2026/04/27 | DDI RULE 5782 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5782 |
| DDI RULE 5783 | CVE-2026-20133 - CISCO TRAVERSAL EXPLOIT - HTTP(Request) | MEDIUM | | 2026/04/27 | DDI RULE 5783 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5783 |
| DDI RULE 5778 | AXIOSRAT BACKDOOR - HTTP(REQUEST) | HIGH | | 2026/04/23 | DDI RULE 5778 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5778 |
| DDI RULE 5779 | CVE-2024-1781 - Totolink CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/04/23 | DDI RULE 5779 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5779 |
| DDI RULE 5780 | CVE-2025-5504 - Totolink CMD INJ Exploit - HTTP(Request) | HIGH | | 2026/04/23 | DDI RULE 5780 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5780 |
| DDI RULE 5768 | SERVER ERROR CODE - HTTP(Response) | HIGH | | 2026/04/22 | DDI RULE 5768 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5768 |
| DDI RULE 5777 | CVE-2025-9816 - WORDPRESS XSS EXPLOIT - HTTP(Request) | HIGH | | 2026/04/22 | DDI RULE 5777 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5777 |
| DDI RULE 5771 | Dlink TRENDnet CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/04/21 | DDI RULE 5771 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5771 |
| DDI RULE 5772 | CVE-2025-13444 - Progress CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/04/21 | DDI RULE 5772 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5772 |
| DDI RULE 5773 | Hytec Inter CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/04/21 | DDI RULE 5773 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5773 |
| DDI RULE 5774 | CVE-2020-10987 - Tenda CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/04/21 | DDI RULE 5774 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5774 |
| DDI RULE 5775 | CVE-2025-13447 - Progress CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/04/21 | DDI RULE 5775 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5775 |
| DDI RULE 5776 | CVE-2025-46704 - Advantech Traversal Exploit - HTTP(Request) | HIGH | | 2026/04/21 | DDI RULE 5776 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5776 |
| DDI RULE 5770 | CVE-2026-25623 -Arista NG Firewall ExecManager Command Injection Exploit - HTTP(Request) | HIGH | | 2026/04/20 | DDI RULE 5770 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5770 |
| DDI RULE 5769 | CVE-2026-26988 - LibreNMS ajax_table SQL Injection Exploit - HTTP(Request) | HIGH | | 2026/04/20 | DDI RULE 5769 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5769 |
| DDI RULE 5766 | SQL INJECT EXPLOIT - HTTP2(Request) | HIGH | | 2026/04/16 | DDI RULE 5766 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5766 |
| DDI RULE 5767 | OFFICESCAN TRAVERSAL EXPLOIT - HTTP(Request) | HIGH | | 2026/04/16 | DDI RULE 5767 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5767 |
| DDI RULE 5765 | CVE-2026-32201 - Sharepoint Auth Bypass EXPLOIT - HTTP (Request) | HIGH | | 2026/04/15 | DDI RULE 5765 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5765 |
| DDI RULE 5747 | Netgate pfSense Directory Traversal Exploit - HTTP(Request) | HIGH | | 2026/04/14 | DDI RULE 5747 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5747 |
| DDI RULE 5755 | CVE-2026-20122 - CISCO TRAVERSAL EXPLOIT - HTTP(Request) | HIGH | | 2026/04/14 | DDI RULE 5755 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5755 |
| DDI RULE 5756 | CVE-2025-68165 - JETBRAINS EXPLOIT - HTTP(Request) | HIGH | | 2026/04/14 | DDI RULE 5756 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5756 |
| DDI RULE 5757 | CVE-2026-28292 - NODEJS EXPLOIT - HTTP(Request) | HIGH | | 2026/04/14 | DDI RULE 5757 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5757 |
| DDI RULE 5758 | CVE-2026-25620 - NG FIREWALL EXPLOIT - HTTP(Request) | HIGH | | 2026/04/14 | DDI RULE 5758 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5758 |
| DDI RULE 5764 | CVE-2026-24848 - OpenEMR EtherFaxActions.php Traversal Exploit - HTTP(Request) | HIGH | | 2026/04/14 | DDI RULE 5764 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5764 |
| DDI RULE 5754 | CVE-2026-25746 - OPENEMR SQL EXPLOIT - HTTP(Request) | HIGH | | 2026/04/13 | DDI RULE 5754 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5754 |
| DDI RULE 5759 | CVE-2025-53679 - FORTINET RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/04/13 | DDI RULE 5759 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5759 |
| DDI RULE 5760 | CVE-2025-8518 - VVVEB RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/04/13 | DDI RULE 5760 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5760 |
| DDI RULE 5761 | Github Repository Code Injection Exploit - HTTP (Response) | HIGH | | 2026/04/13 | DDI RULE 5761 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5761 |
| DDI RULE 5748 | CVE-2026-26990 - LIBRENMS SQL EXPLOIT - HTTP(Request) | HIGH | | 2026/04/13 | DDI RULE 5748 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5748 |
| DDI RULE 5762 | OpenAI Codex Code Injection Exploit - HTTP (Response) | HIGH | | 2026/04/13 | DDI RULE 5762 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5762 |
| DDI RULE 5750 | Active Directory Enumeration Tool - LDAP (Request) | HIGH | | 2026/04/10 | DDI RULE 5750 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5750 |
| DDI RULE 5751 | Primary Domain Controller Sensor - DNS (Response) | HIGH | | 2026/04/10 | DDI RULE 5751 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5751 |
| DDI RULE 5752 | Global Catalog Server Sensor - DNS (Response) | HIGH | | 2026/04/10 | DDI RULE 5752 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5752 |
| DDI RULE 5753 | Kerberos Key Distribution Center Sensor - DNS (Response) | HIGH | | 2026/04/10 | DDI RULE 5753 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5753 |
| DDI RULE 5749 | CVE-2025-71243 - SPIP RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/04/08 | DDI RULE 5749 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5749 |
| DDI RULE 5848 | CVE-2026-26990 - LIBRENMS SQL EXPLOIT - HTTP(Request) | HIGH | | 2026/04/08 | DDI RULE 5848 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5848 |
| DDI RULE 5744 | CVE-2025-8311 - DOTCMS SQL Injection Exploit - HTTP(Request) | HIGH | | 2026/04/07 | DDI RULE 5744 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5744 |
| DDI RULE 5745 | CVE-2016-6277 - NetGear CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/04/07 | DDI RULE 5745 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5745 |
| DDI RULE 5746 | CVE-2025-8110 - Gogs RCE Exploit - HTTP(Request) | HIGH | | 2026/04/06 | DDI RULE 5746 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5746 |
| DDI RULE 5743 | CVE-2026-4747 - FreeBSD RCE EXPLOIT - TCP(REQUEST) | MEDIUM | | 2026/04/06 | DDI RULE 5743 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5743 |
| DDI RULE 5706 | CVE-2026-1603 - Ivanti Endpoint Manager Authentication Bypass Exploit - HTTP(Response) | HIGH | | 2026/04/01 | DDI RULE 5706 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5706 |
| DDI RULE 5728 | CVE-2025-69516 - Tactical RRM RCE Exploit - HTTP(Response) | HIGH | | 2026/04/01 | DDI RULE 5728 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5728 |
| DDI RULE 5740 | CVE-2024-36985 - Splunk RCE Exploit - HTTP(Request) | HIGH | | 2026/03/31 | DDI RULE 5740 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5740 |
| DDI RULE 5741 | CVE-2025-52691 - SmarterMail Arbitrary File Upload Exploit - HTTP(Request) | HIGH | | 2026/03/31 | DDI RULE 5741 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5741 |
| DDI RULE 5742 | CVE-2025-62168 - Squid Authentication Bypass Exploit - HTTP (Response) | MEDIUM | | 2026/03/31 | DDI RULE 5742 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5742 |
| DDI RULE 5736 | CVE-2025-68163 - JETBRAINS EXPLOIT - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5736 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5736 |
| DDI RULE 5731 | CVE-2026-1357 - WORDPRESS WPVIVID EXPLOIT - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5731 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5731 |
| DDI RULE 5732 | CVE-2020-13756 - SABBERWORM EXPLOIT - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5732 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5732 |
| DDI RULE 5733 | CVE-2025-55752 - APACHE TRAVERSAL EXPLOIT - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5733 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5733 |
| DDI RULE 5734 | CVE-2022-36553 - HYTEC CMD INJ EXPLOIT - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5734 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5734 |
| DDI RULE 5735 | CVE-2025-69231 - OPENEMR EXPLOIT - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5735 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5735 |
| DDI RULE 5737 | CVE-2025-59775 - APACHE NTLM EXPLOIT - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5737 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5737 |
| DDI RULE 5738 | CVE-2026-25622 - NG FIREWALL EXPLOIT - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5738 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5738 |
| DDI RULE 5739 | CVE-2026-25253 - Openclaw RCE Exploit - HTTP(Request) | HIGH | | 2026/03/30 | DDI RULE 5739 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5739 |
| DDI RULE 5729 | CVE-2025-7441 - WORDPRESS RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/03/26 | DDI RULE 5729 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5729 |
| DDI RULE 5730 | CVE-2025-55184 - REACT SERVER DOS EXPLOIT - HTTP(Request) | HIGH | | 2026/03/26 | DDI RULE 5730 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5730 |
| DDI RULE 5727 | DNS Query to Public Paste Service Domain - DNS (Response) | HIGH | | 2026/03/24 | DDI RULE 5727 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5727 |
| DDI RULE 5725 | CVE-2026-27180 - MajorDoMo RCE Exploit - HTTP(Request) | HIGH | | 2026/03/23 | DDI RULE 5725 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5725 |
| DDI RULE 5726 | CVE-2025-59922 - Fortinet SQL Injection Exploit - HTTP(Request) | HIGH | | 2026/03/23 | DDI RULE 5726 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5726 |
| DDI RULE 5720 | CVE-2023-7311 - BYTEVALUE CMD INJ Exploit - HTTP(Request) | HIGH | | 2026/03/23 | DDI RULE 5720 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5720 |
| DDI RULE 5718 | Totolink CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/03/19 | DDI RULE 5718 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5718 |
| DDI RULE 5721 | CVE-2025-15467 - OpenSSL CMS Buffer Overflow Exploit - HTTP(Response) | HIGH | | 2026/03/18 | DDI RULE 5721 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5721 |
| DDI RULE 5722 | CVE-2026-1731 - BeyondTrust Remote Support Command Injection Exploit - HTTP(Request) | HIGH | | 2026/03/18 | DDI RULE 5722 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5722 |
| DDI RULE 5723 | CVE-2026-25763 - OPENPROJECT EXPLOIT - HTTP(Request) | HIGH | | 2026/03/18 | DDI RULE 5723 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5723 |
| DDI RULE 5717 | CVE-2026-1367 - Zoho Engine SQL INJ Exploit - HTTP(Request) | HIGH | | 2026/03/18 | DDI RULE 5717 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5717 |
| DDI RULE 5710 | XLL File Download - HTTP (Request) | LOW | | 2026/03/18 | DDI RULE 5710 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5710 |
| DDI RULE 5711 | CVE-2026-2329 - GrandStream GXP1600 Buffer Overflow Exploit - HTTP(Request) | HIGH | | 2026/03/18 | DDI RULE 5711 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5711 |
| DDI RULE 5724 | CVE-2025-54236 - MAGENTO EXPLOIT - HTTP(Request) | HIGH | | 2026/03/18 | DDI RULE 5724 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5724 |
| DDI RULE 5719 | Suspicious Upload/Download to a Public Paste Service - HTTP (Request) | MEDIUM | | 2026/03/18 | DDI RULE 5719 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5719 |
| DDI RULE 5716 | CVE-2026-26216 - CRAWL4AI RCE Exploit - HTTP(Request) | HIGH | | 2026/03/16 | DDI RULE 5716 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5716 |
| DDI RULE 5712 | CVE-2025-0341 - CAMPCODES EXPLOIT - HTTP(Request) | HIGH | | 2026/03/16 | DDI RULE 5712 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5712 |
| DDI RULE 5713 | CVE-2007-1036 - JBOSS JMXCONSOLE EXPLOIT - HTTP(Request) | MEDIUM | | 2026/03/16 | DDI RULE 5713 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5713 |
| DDI RULE 5714 | CVE-2025-68645 - ZIMBRA EXPLOIT - HTTP(Request) | MEDIUM | | 2026/03/16 | DDI RULE 5714 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5714 |
| DDI RULE 5715 | CVE-2026-26190 - MILVUS EXPLOIT - HTTP(Request) | HIGH | | 2026/03/16 | DDI RULE 5715 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5715 |
| DDI RULE 5708 | CVE-2025-0232 - CODEZIPS BLOODBANK EXPLOIT - HTTP(Request) | HIGH | | 2026/03/12 | DDI RULE 5708 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5708 |
| DDI RULE 5709 | CVE-2024-20439 - CISCO CSLU EXPLOIT - HTTP(Request) | HIGH | | 2026/03/12 | DDI RULE 5709 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5709 |
| DDI RULE 5672 | CVE-2025-68613 - N8N RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/03/10 | DDI RULE 5672 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5672 |
| DDI RULE 5673 | CVE-2026-1281 - IVANTI APPSTORE EXPLOIT - HTTP (Request) | HIGH | | 2026/03/10 | DDI RULE 5673 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5673 |
| DDI RULE 5707 | CVE-2025-62521 - CHURCHCRM SETUP EXPLOIT - HTTP(Request) | MEDIUM | | 2026/03/10 | DDI RULE 5707 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5707 |
| DDI RULE 5705 | CVE-2025-10242 - Ivanti Endpoint Manager Mobile CMD Injection Exploit- HTTP(Request) | HIGH | | 2026/03/09 | DDI RULE 5705 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5705 |
| DDI RULE 5698 | CVE-2025-40551 - SolarWinds Web Help Desk RCE Exploit - HTTP(Request) | MEDIUM | | 2026/03/05 | DDI RULE 5698 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5698 |
| DDI RULE 5699 | CVE-2023-23752 - JOOMLA API EXPLOIT - HTTP(Request) | MEDIUM | | 2026/03/05 | DDI RULE 5699 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5699 |
| DDI RULE 5700 | CVE-2023-45852 - Vitogate CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/03/05 | DDI RULE 5700 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5700 |
| DDI RULE 5701 | CVE-2025-68705 - HTTP2 RUSTFS DIRECTORY TRAVERSAL EXPLOIT - TCP(REQUEST) | HIGH | | 2026/03/05 | DDI RULE 5701 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5701 |
| DDI RULE 5702 | CVE-2025-52694 - IOTSUITE SQL INJECTION EXPLOIT - HTTP(Request) | MEDIUM | | 2026/03/05 | DDI RULE 5702 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5702 |
| DDI RULE 5703 | CVE-2025-14094 - EDIMAX CMD INJECTION EXPLOIT - HTTP(Request) | MEDIUM | | 2026/03/05 | DDI RULE 5703 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5703 |
| DDI RULE 5704 | CVE-2024-9932 - WUXBLOG CMD INJECTION EXPLOIT - HTTP(Request) | MEDIUM | | 2026/03/05 | DDI RULE 5704 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5704 |
| DDI RULE 5662 | CVE-2025-23970 - WORDPRESS AOT AUTHBYPASS EXPLOIT - HTTP(Request) | HIGH | | 2026/03/05 | DDI RULE 5662 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5662 |
| DDI RULE 5683 | ASHX Webshell Tunneling - HTTP(Response) | HIGH | | 2026/03/04 | DDI RULE 5683 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5683 |
| DDI RULE 5697 | CVE-2024-3721 - TBK DVR RCE - HTTP (Response) | HIGH | | 2026/03/04 | DDI RULE 5697 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5697 |
| DDI RULE 5696 | CVE-2025-34043 - Vacron NVR CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/03/03 | DDI RULE 5696 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5696 |
| DDI RULE 5667 | CVE-2025-64328 - FREEPBX RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/03/03 | DDI RULE 5667 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5667 |
| DDI RULE 5686 | CVE-2020-8813 - Cacti CMD INJ Exploit - HTTP(Request) | HIGH | | 2026/03/02 | DDI RULE 5686 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5686 |
| DDI RULE 5692 | CVE-2025-68926 - RustFS gRPC Exploit - HTTP2(Request) | HIGH | | 2026/03/02 | DDI RULE 5692 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5692 |
| DDI RULE 5694 | CVE-2021-42071 - Visual Tool DVR CMD INJ Exploit - HTTP(Request) | HIGH | | 2026/03/02 | DDI RULE 5694 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5694 |
| DDI RULE 5695 | CVE-2025-3125 - WSO2 CarbonAppUploader Directory Traversal Exploit - HTTP (Request) | MEDIUM | | 2026/03/02 | DDI RULE 5695 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5695 |
| DDI RULE 5687 | CVE-2025-15097 - ALTERYX SERVER EXPLOIT - HTTP(Request) | HIGH | | 2026/02/26 | DDI RULE 5687 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5687 |
| DDI RULE 5688 | CVE-2025-15029 - CENTREON SQL EXPLOIT - HTTP(Request) | HIGH | | 2026/02/26 | DDI RULE 5688 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5688 |
| DDI RULE 5689 | CVE-2025-10985 - IVANTI CONFIG EXPLOIT - HTTP(Request) | HIGH | | 2026/02/26 | DDI RULE 5689 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5689 |
| DDI RULE 5690 | CVE-2025-34176 - PFSENSE SURICATA EXPLOIT - HTTP(Request) | HIGH | | 2026/02/26 | DDI RULE 5690 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5690 |
| DDI RULE 5691 | CVE-2026-23550 - WORDPRESS AUTHBYPASS - HTTP(Request) | HIGH | | 2026/02/26 | DDI RULE 5691 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5691 |
| DDI RULE 5684 | CVE-2026-1340 - Ivanti Endpoint Manager Mobile Code Injection Exploit - HTTP(Request) | HIGH | | 2026/02/26 | DDI RULE 5684 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5684 |
| DDI RULE 5685 | CVE-2023-41011 - China Gateway CMD INJ Exploit - HTTP(Request) | HIGH | | 2026/02/26 | DDI RULE 5685 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5685 |
| DDI RULE 5682 | CVE-2024-53944 - Tuoshi/Dionlink Command Injection Exploit - HTTP (Request) | HIGH | | 2026/02/26 | DDI RULE 5682 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5682 |
| DDI RULE 5666 | CVE-2025-43989 - Shenzhen Tuoshi NR500-EA Command Injection Exploit - HTTP (Request) | HIGH | | 2026/02/26 | DDI RULE 5666 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5666 |
| DDI RULE 5681 | CVE-2023-35885 - CloudPanel Authentication Bypass - HTTP (Request) | MEDIUM | | 2026/02/25 | DDI RULE 5681 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5681 |
| DDI RULE 5660 | CVE-2026-0920 - WORDPRESS PRIVELEGE ESCALATION - HTTP (Request) | HIGH | | 2026/02/25 | DDI RULE 5660 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5660 |
| DDI RULE 5661 | CVE-2026-23760 - SMARTMAIL BYPASS EXPLOIT - HTTP(Request) | MEDIUM | | 2026/02/24 | DDI RULE 5661 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5661 |
| DDI RULE 5657 | CVE-2025-59934 - Formbricks JWT Signature Auth Bypass Exploit - HTTP(Request) | HIGH | | 2026/02/24 | DDI RULE 5657 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5657 |
| DDI RULE 5659 | CVE-2025-67888 - CWB ADMIN EXPLOIT - HTTP(Request) | HIGH | | 2026/02/24 | DDI RULE 5659 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5659 |
| DDI RULE 5663 | CVE-2026-21858 - N8N WEBHOOK CMD INJECTION EXPLOIT - HTTP(Request) | MEDIUM | | 2026/02/24 | DDI RULE 5663 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5663 |
| DDI RULE 5664 | CVE-2025-70974 - FASTJSON CMD INJECTION EXPLOIT - HTTP(Request) | HIGH | | 2026/02/24 | DDI RULE 5664 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5664 |
| DDI RULE 5680 | CVE-2021-29003 - Genexis CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/02/24 | DDI RULE 5680 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5680 |
| DDI RULE 5677 | OPENCLAW WEBSOCKET CONTROLCHANNEL ACTIVITY - HTTP (Response) | HIGH | | 2026/02/23 | DDI RULE 5677 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5677 |
| DDI RULE 5678 | OPENCLAW GATEWAY - HTTP (Response) | HIGH | | 2026/02/23 | DDI RULE 5678 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5678 |
| DDI RULE 5679 | CVE-2026-0767 - Open WebUI Cleartext Transmission of Credentials Information Disclosure Exploit - HTTP(Request) | HIGH | | 2026/02/23 | DDI RULE 5679 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5679 |
| DDI RULE 5665 | Anydesk Variant 2 - HTTPS (Request) | HIGH | | 2026/02/23 | DDI RULE 5665 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5665 |
| DDI RULE 5656 | CVE-2026-20026 - Cisco Snort RCE Exploit - SMB(Request) | HIGH | | 2026/02/23 | DDI RULE 5656 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5656 |
| DDI RULE 5655 | CVE-2025-8943 - Flowise CustomMCP RCE Exploit - HTTP(Request) | HIGH | | 2026/02/18 | DDI RULE 5655 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5655 |
| DDI RULE 5653 | CVE-2020-9374 - TPLink RCE Exploit - HTTP (Request) - Variant 2 | MEDIUM | | 2026/02/16 | DDI RULE 5653 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5653 |
| DDI RULE 5654 | CVE-2025-62368 - Taiga Insecure Deserialization Exploit - HTTP (Request) | HIGH | | 2026/02/16 | DDI RULE 5654 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5654 |
| DDI RULE 5651 | CVE-2025-3616 - WordPress Greenshift Plugin Exploit - HTTP (Request) | MEDIUM | | 2026/02/11 | DDI RULE 5651 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5651 |
| DDI RULE 5648 | CVE-2025-10243 - Ivanti CMD Injection Exploit - HTTP(Request) | HIGH | | 2026/02/10 | DDI RULE 5648 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5648 |
| DDI RULE 5649 | CVE-2025-59284 - Windows NTLM Spoofing Exploit - HTTP (Response) | MEDIUM | | 2026/02/10 | DDI RULE 5649 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5649 |
| DDI RULE 5650 | CVE-2022-31199 - Netwrix Auditor RCE Exploit - TCP (Request) | MEDIUM | | 2026/02/10 | DDI RULE 5650 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5650 |
| DDI RULE 5644 | CVE-2025-64720 - LIBPNG Buffer Overflow Exploit - HTTP (Response) | MEDIUM | | 2026/02/09 | DDI RULE 5644 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5644 |
| DDI RULE 5645 | CVE-2025-69258 - Trend Micro Apex Central LoadLibraryEX RCE Exploit - TCP (Request) | MEDIUM | | 2026/02/09 | DDI RULE 5645 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5645 |
| DDI RULE 5646 | CVE-2025-41115 - Grafana Enterprise SCIM Exploit - HTTP(Request) | MEDIUM | | 2026/02/09 | DDI RULE 5646 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5646 |
| DDI RULE 5647 | CVE-2025-34299 - Monsta FTP RCE EXPLOIT - HTTP(Request) | HIGH | | 2026/02/09 | DDI RULE 5647 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5647 |
| DDI RULE 5643 | CVE-2025-55183 - React Server Information Leak Exploit - HTTP(Request) | MEDIUM | | 2026/02/05 | DDI RULE 5643 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5643 |
| DDI RULE 5641 | CVE-2025-13661 - LOCALHOST CAB TRAVERSAL EXPLOIT - HTTP(Response) | MEDIUM | | 2026/02/04 | DDI RULE 5641 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5641 |
| DDI RULE 5640 | CVE-2025-12197 - EVENTS URILIB EXPLOIT - HTTP(Request) | HIGH | | 2026/02/04 | DDI RULE 5640 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5640 |
| DDI RULE 5642 | CVE-2025-68614 - API GENERIC SCRIPTINJECT EXPLOIT - HTTP(Request) | HIGH | | 2026/02/04 | DDI RULE 5642 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5642 |
| DDI RULE 5604 | CVE-2025-58360 - OSGeo GeoServer SSRF Exploit - HTTP (Response) | MEDIUM | | 2026/02/03 | DDI RULE 5604 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5604 |
| DDI RULE 5637 | CVE-2025-13486 - WordPress RCE Exploit - HTTP (Request) | HIGH | | 2026/02/03 | DDI RULE 5637 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5637 |
| DDI RULE 5636 | CVE-2025-37164 - HPE OneView RCE Exploit - HTTP (Request) | MEDIUM | | 2026/02/03 | DDI RULE 5636 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5636 |
| DDI RULE 5635 | GoBuster - HTTP (Request) | MEDIUM | | 2026/01/29 | DDI RULE 5635 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5635 |
| DDI RULE 5630 | CVE-2023-52163 - Digiever Command Injection Exploit - HTTP (Request) | MEDIUM | | 2026/01/28 | DDI RULE 5630 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5630 |
| DDI RULE 5634 | CVE-2025-7414 -Tenda O3V2 Router Command Injection Vulnerability Exploit - HTTP(Request) | HIGH | | 2026/01/28 | DDI RULE 5634 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5634 |
| DDI RULE 5633 | CVE-2017-18369 - Billion router Command Injection Exploit - HTTP (Request) | HIGH | | 2026/01/28 | DDI RULE 5633 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5633 |
| DDI RULE 5632 | CVE-2018-4063 - Sierra Wireless AirLink Remote Code Execution Exploit - HTTP (Request) | MEDIUM | | 2026/01/28 | DDI RULE 5632 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5632 |
| DDI RULE 5631 | CVE-2018-10561 - Dasan GPON RCE Exploit - HTTP(Request) | HIGH | | 2026/01/28 | DDI RULE 5631 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5631 |
| DDI RULE 5625 | CVE-2023-35813 - Sitecore Remote Code Execution Exploit - HTTP (Request) | MEDIUM | | 2026/01/27 | DDI RULE 5625 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5625 |
| DDI RULE 5618 | CVE-2025-9900 - TIFF File Upload Large Image Length Exploit - HTTP (Response) | HIGH | | 2026/01/27 | DDI RULE 5618 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5618 |
| DDI RULE 5629 | CVE-2026-24061 - GNU InetUtils telnetd AuthBypass Exploit - TCP (Request) | HIGH | | 2026/01/27 | DDI RULE 5629 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5629 |
| DDI RULE 5616 | NTLM Relay via WebDAV PropFind Method - HTTP(Response) | HIGH | | 2026/01/26 | DDI RULE 5616 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5616 |
| DDI RULE 5622 | CVE-2026-0759 - Katana Network Development Starter Kit RCE Exploit - HTTP (Request) | HIGH | | 2026/01/21 | DDI RULE 5622 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5622 |
| DDI RULE 5623 | CVE-2026-0756 - github-kanban-mcp-server execAsync RCE Exploit - HTTP(Request) | HIGH | | 2026/01/21 | DDI RULE 5623 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5623 |
| DDI RULE 5624 | CVE-2026-0772 - Langflow Disk Cache Deserialization RCE Exploit - HTTP(Request) | HIGH | | 2026/01/21 | DDI RULE 5624 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5624 |
| DDI RULE 5626 | CVE-2026-0766 - NOpen WebUI load_tool_module_by_id RCE Exploit - HTTP(Request) | HIGH | | 2026/01/21 | DDI RULE 5626 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5626 |
| DDI RULE 5627 | CVE-2026-0761 - Foundation Agents MetaGPT Mapping RCE Exploit - HTTP(Request) | HIGH | | 2026/01/21 | DDI RULE 5627 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5627 |
| DDI RULE 5620 | CVE-2025-8088 - WinRAR Directory Traversal Exploit - HTTP (Response) | MEDIUM | | 2026/01/19 | DDI RULE 5620 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5620 |
| DDI RULE 5619 | CVE-2025-53645 - Zimbra DOS Exploit - HTTP (Request) | HIGH | | 2026/01/19 | DDI RULE 5619 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5619 |
| DDI RULE 5617 | CVE-2025-55182 - RSC NEXTJS Unicode RCE Exploit - HTTP (Request) | HIGH | | 2026/01/15 | DDI RULE 5617 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5617 |
| DDI RULE 5615 | CVE-2025-15061 - Framelink Figma MCP Server fetchWithRetry RCE Exploit - HTTP(Request) | HIGH | | 2026/01/14 | DDI RULE 5615 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5615 |
| DDI RULE 5594 | CVE-2025-53417 - DIAview Directory Traversal Exploit AG - HTTP(Response) | HIGH | | 2026/01/13 | DDI RULE 5594 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5594 |
| DDI RULE 5613 | CVE-2025-14931 - Hugging Face smolagents Remote Python Executor RCE Exploit - HTTP (Request) | HIGH | | 2026/01/12 | DDI RULE 5613 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5613 |
| DDI RULE 5614 | CVE-2025-64447 - Fortinet FortiWeb ApacheCookie_parse Auth Bypass Exploit - HTTP(Request) | HIGH | | 2026/01/12 | DDI RULE 5614 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5614 |
| DDI RULE 5605 | CVE-2025-59718 - Fortinet FortiOS Authentication Bypass Exploit - HTTP (Response) | MEDIUM | | 2026/01/07 | DDI RULE 5605 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5605 |
| DDI RULE 5603 | CVE-2021-26828 - Mismatch File Upload leading to RCE Exploit - HTTP (Response) | MEDIUM | | 2026/01/06 | DDI RULE 5603 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5603 |
| DDI RULE 5612 | CVE-2025-14500 - IceWarp14 X-File-Operation RCE Exploit - HTTP (Request) | HIGH | | 2026/01/06 | DDI RULE 5612 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5612 |
| DDI RULE 5592 | CVE-2025-12490 - Netgate pfSense Directory Traversal Exploit - HTTP (Request) | HIGH | | 2026/01/05 | DDI RULE 5592 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5592 |
| DDI RULE 5610 | CVE-2025-61734 - Apache Kylin downloadMetadataBackTmpFile Exploit Request - HTTP(Request) | MEDIUM | | 2025/12/29 | DDI RULE 5610 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5610 |
| DDI RULE 5609 | CVE-2023-50291 - Apache Solr Insecure Endpoint Exploit - HTTP (Request) | MEDIUM | | 2025/12/22 | DDI RULE 5609 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5609 |
| DDI RULE 5606 | CVE-2025-62391 - Ivanti Endpoint Manager PatchHistory SQL Inj RCE Exploit - HTTP (Request) | MEDIUM | | 2025/12/18 | DDI RULE 5606 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5606 |
| DDI RULE 5607 | CGI CHANGE PASSWORD EXPLOIT - HTTP(Request) | HIGH | | 2025/12/18 | DDI RULE 5607 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5607 |
| DDI RULE 5599 | CVE-2025-5946 - Centreon Authenticated Remote Code Execution - HTTP (Response) | HIGH | | 2025/12/18 | DDI RULE 5599 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5599 |
| DDI RULE 5601 | IEC61850 MMS SENSOR - TCP (Request) | HIGH | | 2025/12/18 | DDI RULE 5601 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5601 |
| DDI RULE 5587 | PNIO-CM Profinet Sensor - UDP(Request) | HIGH | | 2025/12/18 | DDI RULE 5587 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5587 |
| DDI RULE 5583 | CVE-2025-59538 - Argo CD DOS Exploit - HTTP(Response) | HIGH | | 2025/12/16 | DDI RULE 5583 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5583 |
| DDI RULE 5602 | CVE-2025-12686 - Synology auth_info Overflow Exploit - HTTP(Request) | HIGH | | 2025/12/16 | DDI RULE 5602 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5602 |
| DDI RULE 5600 | CVE-2025-34175 - Netgate pfSense XSS Exploit - HTTP (Request) | HIGH | | 2025/12/15 | DDI RULE 5600 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5600 |
| DDI RULE 5593 | CVE-2025-64163 - DataEase Server SSRF Exploit - HTTP(Request) | MEDIUM | | 2025/12/15 | DDI RULE 5593 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5593 |
| DDI RULE 5591 | Apache Tomcat Improper Encoding Exploit - HTTP (Response) | HIGH | | 2025/12/10 | DDI RULE 5591 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5591 |
| DDI RULE 5597 | CVE-2025-61733 - Apache Kylin Authentication Bypass - HTTP(Request) | MEDIUM | | 2025/12/10 | DDI RULE 5597 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5597 |
| DDI RULE 5596 | (0Day) Microsoft SharePoint GetTransformer Unsafe Reflection Denial-of-Service Vulnerability - HTTP (Request) | HIGH | | 2025/12/10 | DDI RULE 5596 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5596 |
| DDI RULE 5595 | CVE-2025-55182 - RSC NEXTJS RCE Exploit - HTTP (Request) | HIGH | | 2025/12/06 | DDI RULE 5595 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5595 |
| DDI RULE 5584 | CVE-2025-62411 - LibreNMS Alert Transport Stored Cross-Site Scripting Exploit - HTTP(Response) | HIGH | | 2025/12/04 | DDI RULE 5584 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5584 |
| DDI RULE 5585 | Microsoft SharePoint IsAuthorizedType Deserialization of Untrusted Data DoS Exploit - HTTP (Request) | HIGH | | 2025/12/03 | DDI RULE 5585 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5585 |
| DDI RULE 5589 | CVE-2025-40755 - Siemens SINEC NMS System Monitoring SQL Injection Exploit - HTTP(Request) | HIGH | | 2025/12/03 | DDI RULE 5589 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5589 |
| DDI RULE 5582 | MSSQL Successful Logon - TCP(Response) | HIGH | | 2025/12/03 | DDI RULE 5582 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5582 |
| DDI RULE 5590 | NETGEAR DGN1000 Unauthenticated Remote Code Execution - HTTP (Request) | HIGH | | 2025/12/02 | DDI RULE 5590 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5590 |
| DDI RULE 5586 | CVE-2025-61757 - Oracle Fusion Authentication Bypass Exploit - HTTP (Response) | MEDIUM | | 2025/12/01 | DDI RULE 5586 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5586 |
| DDI RULE 5576 | LUMMASTEALER TRAVERSAL - HTTP(Response) | HIGH | | 2025/11/27 | DDI RULE 5576 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5576 |
| DDI RULE 5574 | Possible CVE-2025-64446 - FortiWeb Path Traversal Exploit - HTTP (Response) | MEDIUM | | 2025/11/26 | DDI RULE 5574 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5574 |
| DDI RULE 5575 | Possible CVE-2025-12480 - Gladinet Triofox Authentication Bypass Exploit - HTTP (Response) | MEDIUM | | 2025/11/26 | DDI RULE 5575 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5575 |
| DDI RULE 5558 | CVE-2025-54447 - Samsung MagicINFO 9 Server RCE Exploit - HTTP (Request) | HIGH | | 2025/11/26 | DDI RULE 5558 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5558 |
| DDI RULE 5588 | SHULUD GIT - HTTP(REQUEST) | HIGH | | 2025/11/26 | DDI RULE 5588 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5588 |
| DDI RULE 5581 | CVE-2025-9242 - WatchGuard Firebox Authentication Bypass Exploit - HTTP (Request) | MEDIUM | | 2025/11/24 | DDI RULE 5581 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5581 |
| DDI RULE 5580 | CVE-2025-53378 - Trend Micro Worry-Free Business Security Missing Authentication Exploit - HTTP (Response) | HIGH | | 2025/11/20 | DDI RULE 5580 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5580 |
| DDI RULE 5563 | CVE-2025-12489 - Evernote openBrowser Command Injection Privilege Escalation Exploit - HTTP(Response) | HIGH | | 2025/11/19 | DDI RULE 5563 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5563 |
| DDI RULE 5577 | CVE-2025-6023 - Grafana Labs Cross-Site Scripting Exploit - HTTP (Request) | HIGH | | 2025/11/19 | DDI RULE 5577 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5577 |
| DDI RULE 5578 | CVE-2025-37106 - Hewlett AutoPass License Server Hardcoded Credentials Exploit - TCP (Request) | HIGH | | 2025/11/19 | DDI RULE 5578 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5578 |
| DDI RULE 5579 | CVE-2025-27225 - TRUfusion Enterprise Unauthenticated Information-Disclosure Exploit - HTTP(Response) | HIGH | | 2025/11/19 | DDI RULE 5579 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5579 |
| DDI RULE 5531 | SUSPICIOUS LOGIN SUCCESS - HTTP(Request) | HIGH | | 2025/11/18 | DDI RULE 5531 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5531 |
| DDI RULE 5532 | WEBSOCKET SSH TUNNEL - HTTP(Request) | MEDIUM | | 2025/11/18 | DDI RULE 5532 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5532 |
| DDI RULE 5561 | CVE-2025-12488 - oobabooga Reliance on Untrusted Inputs Remote Code Execution Exploit - HTTP(Request) | HIGH | | 2025/11/17 | DDI RULE 5561 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5561 |
| DDI RULE 5565 | CVE-2025-48703 - CentOS Web Panel Command Injection Exploit - HTTP (Request) | MEDIUM | | 2025/11/13 | DDI RULE 5565 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5565 |
| DDI RULE 5571 | Suspicious HASSH Client - SSH (Request) | HIGH | | 2025/11/12 | DDI RULE 5571 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5571 |
| DDI RULE 5570 | CVE-2025-62389 - Ivanti Endpoint Manager SQL Injection Exploit - HTTP (Request) | MEDIUM | | 2025/11/11 | DDI RULE 5570 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5570 |
| DDI RULE 5567 | PromptLock AI Ransomware - HTTP (Request) | HIGH | | 2025/11/11 | DDI RULE 5567 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5567 |
| DDI RULE 5568 | Microsoft Exchange PowerShell NTLM Relay Exploit - HTTP(Request) | HIGH | | 2025/11/11 | DDI RULE 5568 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5568 |
| DDI RULE 5569 | CVE-2025-62383 - Ivanti Endpoint Manager SQL Injection Exploit - HTTP (Request) | MEDIUM | | 2025/11/11 | DDI RULE 5569 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5569 |
| DDI RULE 5564 | CVE-2025-10203 - Digilent WaveForms DWF3WORK File Traversal Exploit - HTTP(Response) | MEDIUM | | 2025/11/10 | DDI RULE 5564 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5564 |
| DDI RULE 5566 | MSSQL Unsuccessful Logon - TCP(Response) | HIGH | | 2025/11/06 | DDI RULE 5566 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5566 |
| DDI RULE 5562 | CVE-2025-24893 - XWiki SolrSearchMacros text Code Injection Exploit - HTTP(Response) | HIGH | | 2025/11/05 | DDI RULE 5562 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5562 |
| DDI RULE 5557 | CVE-2025-37107 - Hewlett AutoPass License Server Authentication Bypass Exploit - TCP (Request) | HIGH | | 2025/11/04 | DDI RULE 5557 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5557 |
| DDI RULE 5559 | LLMNR Query Response - Variant 2 | MEDIUM | | 2025/10/30 | DDI RULE 5559 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5559 |
| DDI RULE 5560 | CVE-2025-54926 - Ecostruxure Traversal Exploit - HTTP(Request) | HIGH | | 2025/10/29 | DDI RULE 5560 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5560 |
| DDI RULE 5547 | CVE-2025-6806 - Marvell QConvergeConsole decryptFile Directory Traversal Exploit - HTTP(Response) | HIGH | | 2025/10/29 | DDI RULE 5547 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5547 |
| DDI RULE 5551 | CVE-2025-25271 - Phoenix Contact CHARX SEC-3150 OCPP Authentication Bypass Exploit - HTTP(Response) | HIGH | | 2025/10/29 | DDI RULE 5551 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5551 |
| DDI RULE 5544 | CVE-2025-6801 - Marvell QConvergeConsole Directory Traversal Exploit - HTTP(Response) | HIGH | | 2025/10/28 | DDI RULE 5544 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5544 |
| DDI RULE 5556 | QNAP TS-464 Authentication Bypass Vulnerability - HTTP (Request) | HIGH | | 2025/10/28 | DDI RULE 5556 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5556 |
| DDI RULE 5545 | CVE-2025-6805 - Marvell QConvergeConsole Directory Traversal Exploit - HTTP(Response) | HIGH | | 2025/10/27 | DDI RULE 5545 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5545 |
| DDI RULE 5553 | Oracle E-Business Remote Code Execution Exploit Sensor - HTTP(Response) | HIGH | | 2025/10/27 | DDI RULE 5553 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5553 |
| DDI RULE 5554 | CVE-2025-5947 - WordPress Authentication Bypass Exploit- HTTP(Request) | HIGH | | 2025/10/27 | DDI RULE 5554 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5554 |
| DDI RULE 5555 | CVE-2025-8426 - Marvell QConvergeConsole Directory Traversal Exploit - HTTP (Request) | HIGH | | 2025/10/27 | DDI RULE 5555 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5555 |
| DDI RULE 5552 | CVE-2025-8297 - Ivanti Avalanche RCE Exploit - HTTP(Request) | MEDIUM | | 2025/10/22 | DDI RULE 5552 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5552 |
| DDI RULE 5540 | CVE-2025-5961 - AJAX EXPLOIT - HTTP(Response) | HIGH | | 2025/10/22 | DDI RULE 5540 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5540 |
| DDI RULE 5550 | CVE-2025-40775 - ISC Bind DOS Exploit - DNS(Request) | HIGH | | 2025/10/21 | DDI RULE 5550 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5550 |
| DDI RULE 5542 | CVE-2025-54466 - RCE APACHE EXPLOIT - HTTP(Request) | HIGH | | 2025/10/16 | DDI RULE 5542 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5542 |
| DDI RULE 5534 | Samsung MagicINFO 9 Traversal RCE Exploit - HTTP(Request) | HIGH | | 2025/10/16 | DDI RULE 5534 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5534 |
| DDI RULE 5548 | CVE-2025-53609 - Fortinet FortiWeb Directory Traversal Exploit - HTTP(Response) | HIGH | | 2025/10/16 | DDI RULE 5548 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5548 |
| DDI RULE 5516 | CVE-2019-12526 - SQUID EXPLOIT - HTTP(Response) | HIGH | | 2025/10/16 | DDI RULE 5516 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5516 |
| DDI RULE 5546 | POSSIBLE WSUS RCE EXPLOIT - HTTP(Request) | HIGH | | 2025/10/15 | DDI RULE 5546 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5546 |
| DDI RULE 5521 | CVE-2025-10035 - Fortra GoAnywhere MFT Deserialization Exploit - HTTP (Response) | MEDIUM | | 2025/10/14 | DDI RULE 5521 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5521 |
| DDI RULE 5541 | Machine requested TGS for Administrator - Kerberos (Request) | MEDIUM | | 2025/10/13 | DDI RULE 5541 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5541 |
| DDI RULE 5543 | Suspicious SAMR Enumeration via Endpoint Mapper Sensor - DCE-RPC (Request) | MEDIUM | | 2025/10/13 | DDI RULE 5543 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5543 |
| DDI RULE 5515 | Matchboil Downloader- HTTP (Request) | HIGH | | 2025/10/13 | DDI RULE 5515 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5515 |
| DDI RULE 5526 | SPOOLSS Enumeration via Endpoint Mapper Sensor - DCE-RPC (Request) | HIGH | | 2025/10/13 | DDI RULE 5526 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5526 |
| DDI RULE 5530 | DNS Query for SOA Record Sensor - DNS (Response) | MEDIUM | | 2025/10/13 | DDI RULE 5530 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5530 |
| DDI RULE 5535 | CVE-2025-7913 - TOTOLINK Buffer Overflow Exploit - TCP(Request) | MEDIUM | | 2025/10/09 | DDI RULE 5535 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5535 |
| DDI RULE 5537 | CVE-2025-52367 - PivotX CMS Cross Site Scripting Exploit- HTTP(Request) | HIGH | | 2025/10/09 | DDI RULE 5537 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5537 |
| DDI RULE 5519 | CVE-2025-53417 - DIAview Directory Traversal Exploit - HTTP(Response) | HIGH | | 2025/10/09 | DDI RULE 5519 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5519 |
| DDI RULE 5511 | CVE-2025-26319 - FlowiseAI Flowise attachments Directory Traversal Exploit - HTTP(Response) | HIGH | | 2025/10/09 | DDI RULE 5511 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5511 |
| DDI RULE 5539 | CVE-2025-7912 - TOTOLINK Buffer Overflow Exploit - TCP(Request) | MEDIUM | | 2025/10/09 | DDI RULE 5539 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5539 |
| DDI RULE 5522 | CVE-2025-1829 - TOTOLINK Command Injection Exploit - HTTP(Request) | HIGH | | 2025/10/08 | DDI RULE 5522 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5522 |
| DDI RULE 5524 | NetExec PetitPotam RCE Attempt - HTTP (Request) | HIGH | | 2025/10/08 | DDI RULE 5524 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5524 |
| DDI RULE 5538 | CVE-2025-59528 - Flowise CustomMCP Remote Code Execution Exploit- HTTP(Request) | HIGH | | 2025/10/08 | DDI RULE 5538 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5538 |
| DDI RULE 5533 | Samsung MagicINFO 9 File RCE Exploit - HTTP(Request) | HIGH | | 2025/10/08 | DDI RULE 5533 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5533 |
| DDI RULE 5527 | Suspicious Search DNS Node Object Query - LDAP (Request) | HIGH | | 2025/10/08 | DDI RULE 5527 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5527 |
| DDI RULE 5529 | AddRequest to DomainDnsZones Sensor - LDAP (Request) | MEDIUM | | 2025/10/08 | DDI RULE 5529 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5529 |
| DDI RULE 5536 | CVE-2025-61882 - Oracle Remote Code Execution Exploit - HTTP(Request) | MEDIUM | | 2025/10/07 | DDI RULE 5536 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5536 |
| DDI RULE 5525 | Impacket RCE Attempt - HTTP (Request) | HIGH | | 2025/10/06 | DDI RULE 5525 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5525 |
| DDI RULE 5488 | CVE-2025-20352 - Cisco IOS and IOS XE Overflow Exploit - SNMP(Request) | MEDIUM | | 2025/10/06 | DDI RULE 5488 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5488 |
| DDI RULE 5514 | EncryptHubRecon Trojan - HTTP (Request) | HIGH | | 2025/10/06 | DDI RULE 5514 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5514 |
| DDI RULE 5517 | CVE-2025-26399 - Solarwinds RCE Exploit - HTTP(Request) | MEDIUM | | 2025/10/02 | DDI RULE 5517 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5517 |
| DDI RULE 5513 | RevLynx Backdoor - HTTP (Request) | HIGH | | 2025/10/02 | DDI RULE 5513 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5513 |
| DDI RULE 5520 | CVE-2025-25256 - Fortinet FortiSIEM Command Injection - TCP(Request) | MEDIUM | | 2025/10/02 | DDI RULE 5520 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5520 |
| DDI RULE 5518 | CVE-2025-32821 - Sonic Wall Directory Traversal Exploit - HTTP (Request) | HIGH | | 2025/10/01 | DDI RULE 5518 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5518 |
| DDI RULE 5512 | CVE-2025-53772 - Web Deploy RCE Exploit - HTTP (Request) | HIGH | | 2025/10/01 | DDI RULE 5512 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5512 |
| DDI RULE 5505 | CVE-2025-7775 - NetScaler ADC and NetScaler Gateway Remote Code Execution - HTTP(Response) | MEDIUM | | 2025/09/23 | DDI RULE 5505 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5505 |
| DDI RULE 5510 | CVE-2025-40597 - SonicWall SMA100 Heap Buffer Overflow Exploit - HTTP(Request) | HIGH | | 2025/09/23 | DDI RULE 5510 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5510 |
| DDI RULE 5509 | CVE-2025-53475 - Advantech iView NetworkServlet SQL Injection Exploit - HTTP(Response | HIGH | | 2025/09/23 | DDI RULE 5509 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5509 |
| DDI RULE 5496 | CVE-2025-1302 JSONPath-Plus Remote Code Execution Exploit Attempt - HTTP (Request) | HIGH | | 2025/09/22 | DDI RULE 5496 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5496 |
| DDI RULE 5506 | MCP Server Prompt Lists - HTTP(Request) | HIGH | | 2025/09/17 | DDI RULE 5506 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5506 |
| DDI RULE 5507 | MCP Server Prompt Get - HTTP(Request) | HIGH | | 2025/09/17 | DDI RULE 5507 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5507 |
| DDI RULE 5508 | MCP Server Client Notification - HTTP(Request) | HIGH | | 2025/09/17 | DDI RULE 5508 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5508 |
| DDI RULE 5504 | CVE-2024-8069 - Citrix Session Recording Remote Code Execution Exploit - HTTP (Request) | HIGH | | 2025/09/16 | DDI RULE 5504 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5504 |
| DDI RULE 5482 | MCP Server Tools Discovery - HTTP (Request) | HIGH | | 2025/09/15 | DDI RULE 5482 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5482 |
| DDI RULE 5483 | MCP Server Tools Execution - HTTP (Request) | HIGH | | 2025/09/15 | DDI RULE 5483 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5483 |
| DDI RULE 5484 | MCP Server Resource Discovery - HTTP (Request) | HIGH | | 2025/09/15 | DDI RULE 5484 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5484 |
| DDI RULE 5485 | MCP Server Resource Retrieval - HTTP (Request) | HIGH | | 2025/09/15 | DDI RULE 5485 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5485 |
| DDI RULE 5503 | CVE-2025-54918 - PRIVILEGE ESCALATION EXPLOIT - DCERPC (Response) | HIGH | | 2025/09/11 | DDI RULE 5503 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5503 |
| DDI RULE 5502 | CVE-2025-54309 CrushFTP Authentication Bypass Exploit - HTTP (Response) | MEDIUM | | 2025/09/11 | DDI RULE 5502 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5502 |
| DDI RULE 5501 | CVE-2024-51092 - LibreNMS Command Injection - HTTP (Request) | MEDIUM | | 2025/09/10 | DDI RULE 5501 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5501 |
| DDI RULE 5499 | Possible CVE-2023-23752 Authentication Bypass Exploit - HTTP (Response) | MEDIUM | | 2025/09/09 | DDI RULE 5499 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5499 |
| DDI RULE 5497 | UDP Controller - UDP (Request) | HIGH | | 2025/09/08 | DDI RULE 5497 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5497 |
| DDI RULE 5495 | CVE-2025-54253 Adobe EM Remote Code Execution Exploit - HTTP (Request) | MEDIUM | | 2025/09/03 | DDI RULE 5495 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5495 |
| DDI RULE 5494 | CVE-2025-23318 - NVIDIA Triton Inference Server IPC Remote Code Execution Exploit - HTTP (Response) | HIGH | | 2025/09/01 | DDI RULE 5494 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5494 |
| DDI RULE 5493 | CVE-2025-23320 - NVIDIA Triton SharedMemoryManager Information Disclosure Exploit - HTTP (Request) | HIGH | | 2025/09/01 | DDI RULE 5493 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5493 |
| DDI RULE 5490 | MCP Sampling Request - HTTP (Request) | HIGH | | 2025/08/28 | DDI RULE 5490 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5490 |
| DDI RULE 5491 | MCP Elicitation Request - HTTP (Request) | HIGH | | 2025/08/28 | DDI RULE 5491 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5491 |
| DDI RULE 5492 | CVE-2013-3893 MS Internet Explorer RCE Exploit - HTTP (Response) | LOW | | 2025/08/28 | DDI RULE 5492 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5492 |
| DDI RULE 5481 | MCP Initialize Communication - HTTP (Response) | HIGH | | 2025/08/27 | DDI RULE 5481 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5481 |
| DDI RULE 5480 | Malicious PKL Extension Sensor - HTTP (Response) | MEDIUM | | 2025/08/20 | DDI RULE 5480 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5480 |
| DDI RULE 5486 | CVE-2025-53778 - PRIVILEGE ESCALATION EXPLOIT - DCERPC (Response) | HIGH | | 2025/08/20 | DDI RULE 5486 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5486 |
| DDI RULE 5479 | CVE-2024-1212 Progress Kemp LoadMaster Command Injection Exploit - HTTP (Request) | MEDIUM | | 2025/08/14 | DDI RULE 5479 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5479 |
| DDI RULE 5478 | CVE-2025-49718 - SQL SERVER INFO DISCLOSURE - TCP (Request) | HIGH | | 2025/08/14 | DDI RULE 5478 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5478 |
| DDI RULE 5476 | CVE-2024-7399 - MAGICINFO PATH TRAVERSAL - HTTP (Request) | HIGH | | 2025/08/14 | DDI RULE 5476 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5476 |
| DDI RULE 5477 | CISCO ISE RCE - HTTP (Request) | HIGH | | 2025/08/14 | DDI RULE 5477 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5477 |
| DDI RULE 5464 | CVE-2023-7028 Authentication Bypass Exploit - HTTP (Request) | MEDIUM | | 2025/08/14 | DDI RULE 5464 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5464 |
| DDI RULE 5474 | CVE-2025-7910 - D-Link DIR-513 1.10 curTime leads to Buffer Overflow Exploit - HTTP (Request) | HIGH | | 2025/08/14 | DDI RULE 5474 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5474 |
| DDI RULE 5468 | CVE-2025-4427 and CVE-2025-4428 Authentication Bypass Exploit - HTTP (Response) | HIGH | | 2025/08/14 | DDI RULE 5468 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5468 |
| DDI RULE 5475 | CVE-2025-7862 - TOTOLINK Improper Authentication Exploit - HTTP (Request) | HIGH | | 2025/08/13 | DDI RULE 5475 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5475 |
| DDI RULE 5472 | CVE-2022-46169 - Cacti Command Injection Exploit - HTTP (Request) | HIGH | | 2025/08/12 | DDI RULE 5472 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5472 |
| DDI RULE 5465 | RAVEN STEALER DATAEXFIL - HTTP (Request) | HIGH | | 2025/08/11 | DDI RULE 5465 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5465 |
| DDI RULE 5469 | CVE-2025-54440 - SAMSUNG MAGICINFO RCE EXPLOIT - HTTP (Request) | HIGH | | 2025/08/11 | DDI RULE 5469 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5469 |
| DDI RULE 5470 | CVE-2025-34112 - RIVERBED SQLINJECTION - HTTP (Request) | HIGH | | 2025/08/11 | DDI RULE 5470 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5470 |
| DDI RULE 5471 | CVE-2025-4779 - LUNARYAI XSS - HTTP (Request) | HIGH | | 2025/08/11 | DDI RULE 5471 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5471 |
| DDI RULE 5463 | Trend Micro ApexOne Command Injection Exploit Attempt - HTTP (Request) | MEDIUM | | 2025/08/06 | DDI RULE 5463 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5463 |
| DDI RULE 5467 | CVE-2025-6811 - MESCIUS ACTIVEREPORTSNET RCE - HTTP (Response) | HIGH | | 2025/08/06 | DDI RULE 5467 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5467 |
| DDI RULE 5466 | CVE-2023-2533 - PAPERCUT CSRF EXPLOIT - HTTP (Request) | HIGH | | 2025/08/06 | DDI RULE 5466 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5466 |
| DDI RULE 5451 | CVE-2019-9621 - Zimbra SSRF Exploit - HTTP (Response) | MEDIUM | | 2025/08/04 | DDI RULE 5451 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5451 |
| DDI RULE 5445 | CVE-2025-25257 - FortiWeb SQL Injection Exploit - HTTP (Response) | MEDIUM | | 2025/08/04 | DDI RULE 5445 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5445 |
| DDI RULE 5455 | CVE-2024-54085 - AMI AUTHBYPASS EXPLOIT - HTTP (Request) | HIGH | | 2025/07/30 | DDI RULE 5455 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5455 |
| DDI RULE 5456 | CVE-2025-6802 - MARVELL QCONVERGECONSOLE RCE EXPLOIT ATTEMPT - HTTP (Request) | HIGH | | 2025/07/30 | DDI RULE 5456 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5456 |
| DDI RULE 5457 | CVE-2025-6794 - MARVELL QCONVERGECONSOLE RCE EXPLOIT ATTEMPT - HTTP (Request) | HIGH | | 2025/07/30 | DDI RULE 5457 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5457 |
| DDI RULE 5460 | CVE-2023-34048 - VMware vCenter Server Authentication Pointer Use of Out-of-range Pointer Offset Exploit - TCP (Request) | HIGH | | 2025/07/30 | DDI RULE 5460 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5460 |
| DDI RULE 5462 | CVE-2025-47981 - NEGOEX RCE Exploit- SMB2 (Request) | HIGH | | 2025/07/30 | DDI RULE 5462 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5462 |
| DDI RULE 5423 | SockDetours Magic Number - TCP(Request) | HIGH | | 2025/07/29 | DDI RULE 5423 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5423 |
| DDI RULE 5439 | CVE-2025-47812 - Wing FTP Server Command Injection Exploit - HTTP (Response) | MEDIUM | | 2025/07/29 | DDI RULE 5439 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5439 |
| DDI RULE 5444 | CVE-2025-20281 - CISCO ISE ERS RCE - HTTP (Request) | HIGH | | 2025/07/28 | DDI RULE 5444 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5444 |
| DDI RULE 5452 | CVE-2025-20281 - Cisco Identity Services Engine RCE Exploit - HTTP(Request) | HIGH | | 2025/07/25 | DDI RULE 5452 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5452 |
| DDI RULE 5454 | CVE-2025-20282 - Cisco Identity Services Engine File Upload Exploit - HTTP(Request) | HIGH | | 2025/07/25 | DDI RULE 5454 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5454 |
| DDI RULE 5453 | CVE-2025-20337 - Cisco Identity Services Engine Deserialization RCE Exploit - HTTP(Request) | HIGH | | 2025/07/25 | DDI RULE 5453 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5453 |
| DDI RULE 5447 | NETBIOS DEVICES DISCOVERY - UDP(RESPONSE) | HIGH | | 2025/07/23 | DDI RULE 5447 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5447 |
| DDI RULE 5449 | CVE-2021-28474 - Sharepoint Server RCE Exploit - HTTP(Request) | MEDIUM | | 2025/07/22 | DDI RULE 5449 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5449 |
| DDI RULE 5440 | CVE-2024-28988 - SOLARWINDS RCE - HTTP (Request) | HIGH | | 2025/07/22 | DDI RULE 5440 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5440 |
| DDI RULE 5442 | CVE-2025-6543 - CITRIX NETSCALERADC MEMLEAK - HTTP (Request) | HIGH | | 2025/07/22 | DDI RULE 5442 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5442 |
| DDI RULE 5446 | CVE-2025-53770 - Sharepoint Deserialization Exploit - HTTP (Request) | MEDIUM | | 2025/07/22 | DDI RULE 5446 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5446 |
| DDI RULE 5424 | Encoded EXE File transfer - FTP(Request) | HIGH | | 2025/07/22 | DDI RULE 5424 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5424 |
| DDI RULE 5438 | ONELOGIN ADMINAPI - HTTP (Request) | HIGH | | 2025/07/17 | DDI RULE 5438 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5438 |
| DDI RULE 5441 | CVE-2024-3721 - TBK DVR RCE - HTTP (Request) | HIGH | | 2025/07/17 | DDI RULE 5441 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5441 |
| DDI RULE 5443 | CVE-2025-5777 - CITRIX BLEED MEMORY OVERFLOW - HTTP (Request) | HIGH | | 2025/07/17 | DDI RULE 5443 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5443 |
| DDI RULE 5437 | Possible DNS Tunneling - DNS (Response) - Variant 3 | LOW | | 2025/07/16 | DDI RULE 5437 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5437 |
| DDI RULE 5422 | WEBSOCKET UPGRADE - HTTP(Response) | HIGH | | 2025/07/16 | DDI RULE 5422 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5422 |
| DDI RULE 5436 | CVE-2016-10033 - PHPMailer RCE Exploit - HTTP (Request) | MEDIUM | | 2025/07/14 | DDI RULE 5436 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5436 |
| DDI RULE 5432 | CVE-2023-39780 - ASUS Command Injection Exploit - HTTP (Request) | MEDIUM | | 2025/07/09 | DDI RULE 5432 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5432 |
| DDI RULE 5435 | CVE-2025-33073 - Windows SMB Client Elevation of Privilege Vulnerability Exploit - DNS (Response) | MEDIUM | | 2025/07/09 | DDI RULE 5435 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5435 |
| DDI RULE 5434 | APT - BPFDOOR - HTTP(Request) | HIGH | | 2025/07/08 | DDI RULE 5434 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5434 |
| DDI RULE 5430 | Possible WebShell Attempt via PHP Obfuscation - HTTP (Request) - Variant 2 | MEDIUM | | 2025/07/07 | DDI RULE 5430 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5430 |
| DDI RULE 5425 | CVE-2021-32030 - ASUS Router and Lyra Mini Authentication Bypass Exploit - HTTP (Response) | MEDIUM | | 2025/07/07 | DDI RULE 5425 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5425 |
| DDI RULE 5431 | CVE-2025-30397 - JSCRIPT RCE - HTTP (Response) | HIGH | | 2025/07/03 | DDI RULE 5431 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5431 |
| DDI RULE 5433 | APT - BPFDOOR - TCP - Variant 2 | HIGH | | 2025/07/03 | DDI RULE 5433 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5433 |
| DDI RULE 5429 | CVE-2023-33538 - TPLink Command Injection Exploit - HTTP (Request) | MEDIUM | | 2025/06/30 | DDI RULE 5429 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5429 |
| DDI RULE 5428 | CVE-2025-24016 - Wazuh Insecure Deserialization Exploit - HTTP (Request) | HIGH | | 2025/06/30 | DDI RULE 5428 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5428 |
| DDI RULE 5421 | APT - BPFDOOR - UDP | HIGH | | 2025/06/26 | DDI RULE 5421 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5421 |
| DDI RULE 5384 | CVE-2025-32433 - Erlang OTP Server RCE Exploit - SSH (Request) | MEDIUM | | 2025/06/26 | DDI RULE 5384 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5384 |
| DDI RULE 5408 | CVE-2024-56145 - Craft CMS RCE Exploit - HTTP (Response) | MEDIUM | | 2025/06/25 | DDI RULE 5408 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5408 |
| DDI RULE 5417 | CVE-2025-33053 - WEBDAV RCE - HTTP (Response) | HIGH | | 2025/06/24 | DDI RULE 5417 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5417 |
| DDI RULE 5381 | CVE-2025-30406 - GLADINET CENTRESTACK RCE - HTTP (Request) | HIGH | | 2025/06/23 | DDI RULE 5381 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5381 |
| DDI RULE 5420 | APT - BPFDOOR - TCP | HIGH | | 2025/06/19 | DDI RULE 5420 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5420 |
| DDI RULE 5414 | CVE-2025-49220 - APEX CENTRAL RCE - HTTP (Response) | HIGH | | 2025/06/18 | DDI RULE 5414 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5414 |
| DDI RULE 5416 | CVE-2025-49212 - ENDPOINT ENCRYPTION RCE - TCP (Request) | HIGH | | 2025/06/17 | DDI RULE 5416 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5416 |
| DDI RULE 5409 | CVE-2025-2146 - CANON BUFFER OVERFLOW - HTTP (Request) | HIGH | | 2025/06/17 | DDI RULE 5409 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5409 |
| DDI RULE 5415 | CVE-2025-49213 - ENDPOINT ENCRYPTION RCE - TCP (Request) | HIGH | | 2025/06/17 | DDI RULE 5415 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5415 |
| DDI RULE 5389 | FORTISANDBOX RCE EXPLOIT - HTTP(Response) | HIGH | | 2025/06/11 | DDI RULE 5389 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5389 |
| DDI RULE 5393 | CVE-2020-15999 - FREETYPE RCE EXPLOIT - HTTP(Response) | HIGH | | 2025/06/11 | DDI RULE 5393 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5393 |
| DDI RULE 5368 | CVE-2022-43939 - PENTAHO AUTHBYPASS RCE EXPLOIT - HTTP(Response) | HIGH | | 2025/06/11 | DDI RULE 5368 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5368 |
| DDI RULE 5411 | CVE-2025-3248 - LANGFLOW RCE - HTTP (Request) | HIGH | | 2025/06/10 | DDI RULE 5411 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5411 |
| DDI RULE 5413 | CVE-2025-46337 - ADODB SQL INJECTION - HTTP (Response) | HIGH | | 2025/06/10 | DDI RULE 5413 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5413 |
| DDI RULE 5410 | CVE-2025-24813 - APACHE TOMCAT RCE - HTTP (Request) | HIGH | | 2025/06/10 | DDI RULE 5410 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5410 |
| DDI RULE 5412 | CVE-2025-32756 - FORTINET RCE - HTTP (Request) | HIGH | | 2025/06/10 | DDI RULE 5412 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5412 |
| DDI RULE 5405 | ALLEGRA MULTIPLE DIRECTORY TRAVERSAL EXPLOIT ATTEMPT - HTTP (REQUEST) | HIGH | | 2025/06/05 | DDI RULE 5405 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5405 |
| DDI RULE 5402 | Multiple Occurrences of Negotiate Request Activity Sensor - RDP (Request) | HIGH | | 2025/06/05 | DDI RULE 5402 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5402 |
| DDI RULE 5380 | CVE-2024-11131 - SYNOLOGY BUFFER OVERFLOW - HTTP(RESPONSE) | HIGH | | 2025/06/05 | DDI RULE 5380 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5380 |
| DDI RULE 4590 | VIDAR - HTTP(REQUEST) - Variant 2 | HIGH | | 2025/06/05 | DDI RULE 4590 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-4590 |
| DDI RULE 5404 | CVE-2025-29635 - DLINK COMMAND INJECTION EXPLOIT ATTEMPT- HTTP (REQUEST) | HIGH | | 2025/06/04 | DDI RULE 5404 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5404 |
| DDI RULE 4397 | ACTIVE DIRECTORY GPO DEPLOY COMMAND - SMB2 (Response) | HIGH | | 2025/06/04 | DDI RULE 4397 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-4397 |
| DDI RULE 5403 | CVE-2025-24054 - MSNTLM EXPLOIT - HTTP(Response) | HIGH | | 2025/05/29 | DDI RULE 5403 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5403 |
| DDI RULE 5406 | ECHARGE COMMAND INJECTION EXPLOIT - HTTP (Response) | HIGH | | 2025/05/29 | DDI RULE 5406 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5406 |
| DDI RULE 5329 | CVE-2024-8856 - WordPress Time Capsule Plugin Exploit - HTTP (Response) | MEDIUM | | 2025/05/28 | DDI RULE 5329 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5329 |
| DDI RULE 5395 | IVANTI EPMANAGER EXPLOIT - HTTP(Response) | HIGH | | 2025/05/27 | DDI RULE 5395 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5395 |
| DDI RULE 5400 | Presence of Angry IP Scanner - DNS (Response) | HIGH | | 2025/05/27 | DDI RULE 5400 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5400 |
| DDI RULE 5390 | Possible AS-REP Roasting Attack - Kerberos (Request) | HIGH | | 2025/05/26 | DDI RULE 5390 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5390 |
| DDI RULE 5399 | CVE-2019-2729 or CVE-2019-2725 - Oracle Weblogic - HTTP (Request) | MEDIUM | | 2025/05/22 | DDI RULE 5399 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5399 |
| DDI RULE 5372 | SQLMAP Sensor - HTTP (Response) | MEDIUM | | 2025/05/21 | DDI RULE 5372 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5372 |
| DDI RULE 5360 | APT - BPFDOOR - ICMP (Request) | HIGH | | 2025/05/21 | DDI RULE 5360 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5360 |
| DDI RULE 5396 | Suspicious Shell Command in Header - HTTP (Request) | HIGH | | 2025/05/19 | DDI RULE 5396 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5396 |
| DDI RULE 5370 | CVE-2024-41710 - MITEL6800 RCE EXPLOIT - HTTP(Request) | HIGH | | 2025/05/14 | DDI RULE 5370 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5370 |
| DDI RULE 5394 | CVE-2024-57050 - TPLINK EXPLOIT - HTTP(Response) | HIGH | | 2025/05/13 | DDI RULE 5394 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5394 |
| DDI RULE 5371 | CVE-2025-31161 - CRUSHFTP AUTH BYPASS - HTTP (Response) | HIGH | | 2025/05/08 | DDI RULE 5371 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5371 |
| DDI RULE 5365 | CVE-2024-11040 - VLLM DOS EXPLOIT - HTTP (Response) | HIGH | | 2025/05/07 | DDI RULE 5365 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5365 |
| DDI RULE 5391 | CVE-2025-22461 - IVANTI SQLI - HTTP (Response) | HIGH | | 2025/05/07 | DDI RULE 5391 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5391 |
| DDI RULE 5392 | CVE-2024-23468 - SOLARWINDS PATH TRAVERSAL - TCP (Request) | HIGH | | 2025/05/07 | DDI RULE 5392 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5392 |
| DDI RULE 5388 | Invoke Request Activity via DCOM - DCERPC (Request) | MEDIUM | | 2025/05/06 | DDI RULE 5388 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5388 |
| DDI RULE 5387 | CVE-2023-44221 - SONICWALL EXPLOIT COMMAND INJECTION EXPLOIT - HTTP(RESPONSE) | HIGH | | 2025/05/03 | DDI RULE 5387 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5387 |
| DDI RULE 5385 | CVE-2021-47667 - ZENDTO RCE - HTTP (Request) | HIGH | | 2025/04/30 | DDI RULE 5385 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5385 |
| DDI RULE 5382 | CVE-2025-31324 - SAP NETWEAVER UPLOAD EXPLOIT REQUEST - HTTP(REQUEST) | HIGH | | 2025/04/26 | DDI RULE 5382 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5382 |
| DDI RULE 5377 | ROUTER CLEARTEXT PASSWORD DISCLOSURE EXPLOIT - HTTP (Request) | HIGH | | 2025/04/22 | DDI RULE 5377 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5377 |
| DDI RULE 5376 | CVE-2024-11042 - APACHE AI FILE DELETION - HTTP (Request) | HIGH | | 2025/04/21 | DDI RULE 5376 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5376 |
| DDI RULE 5373 | CVE-2025-22457 - XFORWARDEDFOR BUFFER OVERFLOW - HTTP (Request) | HIGH | | 2025/04/16 | DDI RULE 5373 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5373 |
| DDI RULE 5375 | CVE-2024-10188 - LITELLM DOS - HTTP (Request) | HIGH | | 2025/04/16 | DDI RULE 5375 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5375 |
| DDI RULE 5369 | IVANTI TRAVERSAL EXPLOIT - HTTP(Response) | HIGH | | 2025/04/15 | DDI RULE 5369 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5369 |
| DDI RULE 5367 | CVE-2025-30355 - DOS Exploit - HTTP(Response) | HIGH | | 2025/04/15 | DDI RULE 5367 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5367 |
| DDI RULE 5362 | CVE-2025-24893 - XWIKI SOLRSEARCHMACROS RCE - HTTP (Request) | HIGH | | 2025/04/15 | DDI RULE 5362 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5362 |
| DDI RULE 5364 | CVE-2024-8859 - MLFLOW DIRECTORY TRAVERSAL - HTTP (Request) | HIGH | | 2025/04/15 | DDI RULE 5364 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5364 |
| DDI RULE 4462 | Metasploit (Payload) - RC4 Encrypted Reverse TCP - TCP (Request) | MEDIUM | | 2025/04/15 | DDI RULE 4462 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-4462 |
| DDI RULE 5352 | POSSIBLE CVE-2025-21277 - MSMQ BUFFER EXPLOIT - HTTP(Request) | LOW | | 2025/04/03 | DDI RULE 5352 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5352 |
| DDI RULE 5355 | WMI QUERY RCE - DCERPC (Request) | HIGH | | 2025/04/03 | DDI RULE 5355 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5355 |
| DDI RULE 5353 | CVE-2024-45195 - APACHE OFBIZ RCE EXPLOIT - HTTP(Request) | HIGH | | 2025/04/03 | DDI RULE 5353 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5353 |
| DDI RULE 5363 | CVE-2024-50330 - IVANTI SQL INJECTION - HTTP (Response) | HIGH | | 2025/04/02 | DDI RULE 5363 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5363 |
| DDI RULE 5359 | CVE-2018-8639 - Win32k Privilege Escalation Exploit - HTTP (Response) | HIGH | | 2025/03/26 | DDI RULE 5359 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5359 |
| DDI RULE 5326 | IVANTI SQL INJECTION RCE EXPLOIT - HTTP (Request) | HIGH | | 2025/03/26 | DDI RULE 5326 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5326 |
| DDI RULE 5351 | Microsoft Windows Zero Day Vulnerability (ZDI-25-148) - HTTP(Response) | HIGH | | 2025/03/25 | DDI RULE 5351 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5351 |
| DDI RULE 5357 | CVE-2018-9276 - PRTG Command Injection - HTTP (Request) | MEDIUM | | 2025/03/25 | DDI RULE 5357 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5357 |
| DDI RULE 5324 | CVE-2024-43468 - CM SQL INJECTION RCE - HTTP (Response) | HIGH | | 2025/03/24 | DDI RULE 5324 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5324 |
| DDI RULE 5335 | CVE-2025-21377 - NTLM RELAY EXPLOIT - HTTP (Response) | HIGH | | 2025/03/24 | DDI RULE 5335 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5335 |
| DDI RULE 5356 | CVE-2025-29927 - NEXTJS MIDDLEWARE EXPLOIT - HTTP(Response) | HIGH | | 2025/03/24 | DDI RULE 5356 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5356 |
| DDI RULE 5333 | WMI RCE - DCERPC (Request) | HIGH | | 2025/03/19 | DDI RULE 5333 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5333 |
| DDI RULE 5341 | Suspicious Shell Command Sensor - TCP | HIGH | | 2025/03/18 | DDI RULE 5341 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5341 |
| DDI RULE 5338 | CVE-2025-0108 - PALO ALTO AUTH BYPASS EXPLOIT - HTTP (Response) | HIGH | | 2025/03/13 | DDI RULE 5338 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5338 |
| DDI RULE 5342 | ITaskSchedulerService Remote Schedule Tasks (Create) - SMB (Request) | HIGH | | 2025/03/13 | DDI RULE 5342 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5342 |
| DDI RULE 5343 | ITaskSchedulerService Remote Schedule Tasks (Run) - SMB (Request) | HIGH | | 2025/03/13 | DDI RULE 5343 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5343 |
| DDI RULE 5344 | ITaskSchedulerService Remote Schedule Tasks (Delete) - SMB (Request) | HIGH | | 2025/03/13 | DDI RULE 5344 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5344 |
| DDI RULE 5345 | ITaskSchedulerService Remote Schedule Tasks (Create) - SMB2 (Request) | HIGH | | 2025/03/13 | DDI RULE 5345 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5345 |
| DDI RULE 5346 | ITaskSchedulerService Remote Schedule Tasks (Run) - SMB2 (Request) | HIGH | | 2025/03/13 | DDI RULE 5346 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5346 |
| DDI RULE 5347 | ITaskSchedulerService Remote Schedule Tasks (Delete) - SMB2 (Request) | HIGH | | 2025/03/13 | DDI RULE 5347 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5347 |
| DDI RULE 5348 | SVCCTL Create Service - SMB2 (Request) | HIGH | | 2025/03/13 | DDI RULE 5348 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5348 |
| DDI RULE 5336 | CVE-2025-21308 - WINDOWS THEMES SPOOFING EXPLOIT - HTTP (Response) | HIGH | | 2025/03/13 | DDI RULE 5336 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5336 |
| DDI RULE 5349 | SVCCTL Start Service - SMB2 (Request) | HIGH | | 2025/03/13 | DDI RULE 5349 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5349 |
| DDI RULE 5327 | CVE-2024-43365 - CACTI XSS EXPLOIT - HTTP (Response) | HIGH | | 2025/03/12 | DDI RULE 5327 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5327 |
| DDI RULE 5331 | CVE-2024-46909 - WhatsUp Gold WriteDataFile Directory Traversal Exploit - TCP (Request) | HIGH | | 2025/03/11 | DDI RULE 5331 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5331 |
| DDI RULE 5337 | CVE-2024-55591 - FORTINET SECURITY BYPASS EXPLOIT - HTTP (Response) | HIGH | | 2025/03/10 | DDI RULE 5337 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5337 |
| DDI RULE 5334 | CVE-2024-13158 - IVANTI DIRECTORY TRAVERSAL EXPLOIT- HTTP (Request) | HIGH | | 2025/03/05 | DDI RULE 5334 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5334 |
| DDI RULE 5321 | CVE-2025-0105 - Palo Alto Networks Expedition Input Validation Exploit - HTTP (Response) | HIGH | | 2025/03/05 | DDI RULE 5321 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5321 |
| DDI RULE 5340 | LBLINK COMMAND INJECTION EXPLOIT - HTTP (Request) | HIGH | | 2025/03/05 | DDI RULE 5340 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5340 |
| DDI RULE 5332 | CVE-2024-43639 - Microsoft Windows KDC Integer Overflow Exploit - TCP (Response) | HIGH | | 2025/03/04 | DDI RULE 5332 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5332 |
| DDI RULE 5330 | NMAP NetBios Session Service Scan - TCP (Request) | MEDIUM | | 2025/03/03 | DDI RULE 5330 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5330 |
| DDI RULE 5322 | Active Directory Certificate Services Template Discovery - LDAP (Request) - Variant 2 | HIGH | | 2025/03/03 | DDI RULE 5322 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5322 |
| DDI RULE 5313 | CVE-2010-2568 - Windows Shell RCE - HTTP (Response) | MEDIUM | | 2025/02/20 | DDI RULE 5313 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5313 |
| DDI RULE 5323 | CVE-2024-49112 - INTEGER OVERFLOW EXPLOIT - LDAP (Response) | HIGH | | 2025/02/20 | DDI RULE 5323 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5323 |
| DDI RULE 5317 | CVE-2024-56337 - APACHE TOMCAT RCE - HTTP (Response) | HIGH | | 2025/02/19 | DDI RULE 5317 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5317 |
| DDI RULE 5305 | CVE-2024-42327 - Zabbix SQL Injection - HTTP (Response) | HIGH | | 2025/02/18 | DDI RULE 5305 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5305 |
| DDI RULE 5318 | CVE-2025-0282 - IVANTI RCE EXPLOIT - HTTP(Request) | HIGH | | 2025/02/17 | DDI RULE 5318 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5318 |
| DDI RULE 5320 | CVE-2025-0107 - Palo Alto Networks Expedition Insecure Deserialization Exploit - HTTP (Response) | HIGH | | 2025/02/17 | DDI RULE 5320 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5320 |
| DDI RULE 5316 | CVE-2024-37404 - IVANTI RCE EXPLOIT - HTTP (Response) | HIGH | | 2025/02/12 | DDI RULE 5316 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5316 |
| DDI RULE 5314 | ADCS Suspicious use of Certificate - Kerberos (Request) | HIGH | | 2025/02/11 | DDI RULE 5314 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5314 |
| DDI RULE 5310 | CVE-2024-52047 - DIRECTORY TRAVERSAL EXPLOIT - HTTP (Request) | HIGH | | 2025/02/06 | DDI RULE 5310 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5310 |
| DDI RULE 5312 | CVE-2024-40711 - Veeam Backup & Replication Remote Command Execution Exploit - HTTP (Response) | HIGH | | 2025/02/06 | DDI RULE 5312 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5312 |
| DDI RULE 5303 | CVE-2024-51378 - CYBERPANEL RCE EXPLOIT - HTTP (Request) | HIGH | | 2025/02/05 | DDI RULE 5303 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5303 |
| DDI RULE 5311 | CVE-2022-22947 - SPRINGCLOUD RCE EXPLOIT - HTTP (Request) | HIGH | | 2025/02/05 | DDI RULE 5311 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5311 |
| DDI RULE 5292 | CVE-2024-47575 - FORTIMANAGER RCE EXPLOIT - HTTP (Response) | HIGH | | 2025/02/04 | DDI RULE 5292 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5292 |
| DDI RULE 5304 | CVE-2024-12828 - WEBMIN RCE EXPLOIT - HTTP (Response) | HIGH | | 2025/01/30 | DDI RULE 5304 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5304 |
| DDI RULE 5307 | CVE-2024-50388 - QNAP BACKUP EXPLOIT - HTTP(Request) | HIGH | | 2025/01/30 | DDI RULE 5307 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5307 |
| DDI RULE 5306 | CVE-2024-53691 - QNAP RCE - HTTP (Request) | HIGH | | 2025/01/30 | DDI RULE 5306 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5306 |
| DDI RULE 5302 | CVE-2024-8963 - IVANTI AUTH BYPASS EXPLOIT - HTTP (Response) | HIGH | | 2025/01/24 | DDI RULE 5302 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5302 |
| DDI RULE 5300 | CVE-2024-29847 - IVANTI RCE EXPLOIT - TCP (Request) | HIGH | | 2025/01/22 | DDI RULE 5300 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5300 |
| DDI RULE 5301 | CVE-2024-50603 - AVIATRIX COMMAND INJECTION - HTTP (Request) | HIGH | | 2025/01/21 | DDI RULE 5301 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5301 |
| DDI RULE 5247 | Base64 Encoded Cookie Sensor - HTTP (Request) | LOW | | 2025/01/20 | DDI RULE 5247 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5247 |
| DDI RULE 5246 | Entropy Encoded Cookie Sensor - HTTP (Request) | LOW | | 2025/01/20 | DDI RULE 5246 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5246 |
| DDI RULE 5299 | HTTP Websocket Connection to External Server (Request) | LOW | | 2025/01/16 | DDI RULE 5299 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5299 |
| DDI RULE 1268 | Reverse HTTPS Meterpreter detected - Variant 2 | HIGH | | 2025/01/15 | DDI RULE 1268 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-1268 |
| DDI RULE 5298 | CVE-2024-5011 - WHATSUP GOLD EXPLOIT - HTTP (Request) | HIGH | | 2025/01/15 | DDI RULE 5298 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5298 |
| DDI RULE 2744 | OMRON FINS UDP Read Controller Attempt NSE - UDP (Request) | LOW | | 2025/01/13 | DDI RULE 2744 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-2744 |
| DDI RULE 5294 | CVE-2024-38856 - OFBIZ AUTHBYPASS EXPLOIT - HTTP (Response) | HIGH | | 2025/01/08 | DDI RULE 5294 | /vinfo/cn/threat-encyclopedia/network/ddi-rule-5294 |
通过以下社交网站联系我们