Velociraptor
Rapid7- Software type
- —
- Catalog vulnerabilities
- 38
Severity across 2 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 2 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 38 vulnerability records affecting Velociraptor.
Among the 2 records analyzed by CyStack, 2 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-19584Velociraptor VQL injection during notebook restore from backup | Exploitation statusNot known exploited | FixYes | Published09/10/2026 | SeverityHigh |
CVE-2026-19583Velociraptor Required Permissions bypass by using client monitoring queries | Exploitation statusNot known exploited | FixYes | Published09/10/2026 | SeverityCritical |
CVE-2026-19200Velociraptor Analyst overwrites live built-in artifacts through verify() | Exploitation statusNot known exploited | FixYes | Published08/24/2026 | SeverityHigh |
CVE-2026-15371Velociraptor Stored XSS in URL column types | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-18652Velociraptor STACK Type Download Path Bypasses Denied Prefix Check | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityMedium |
CVE-2026-64951Velociraptor DoS triggered by Divide by Zero panic | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityLow |
CVE-2026-64952Velociraptor Hunt Deletion With Insufficient Permission Check | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityMedium |
CVE-2026-64955Velociraptor CSV Formula Injection in Export Pipeline | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityMedium |
CVE-2026-64954Velociraptor collect_client() Permissions Bypass | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityHigh |
CVE-2026-18639Velociraptor OIDC Authenticator susceptible to email spoofing | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityHigh |
CVE-2026-18638Velociraptor server crash via the SetPassword API | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityMedium |
CVE-2026-18640Velociraptor directory traversal via the NewNotebook API | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityHigh |
CVE-2026-18860Velociraptor incorrect Org deletion permissions check | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityHigh |
CVE-2026-17535Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityMedium |
CVE-2026-18636Velociraptor VFSGetBuffer API path deny list bypass | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityMedium |
CVE-2026-18635Velociraptor query plugin allows impersonation in other orgs | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityHigh |
CVE-2026-18972Velociraptor authenticated identity-spoofing vulnerability | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityCritical |
CVE-2026-18348Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityMedium |
CVE-2026-8795CVE-2026-8795 | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityHigh |
CVE-2026-6863HTTP Filestore Endpoints Misapply Permissions Across Organizations | Exploitation statusNot known exploited | FixYes | Published05/06/2026 | SeverityMedium |
CVE-2026-7572Velociraptor EVTX Parser — Process Crash via Crafted .evtx File | Exploitation statusNot known exploited | FixYes | Published05/06/2026 | SeverityMedium |
CVE-2026-7573GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations | Exploitation statusNot known exploited | FixYes | Published05/06/2026 | SeverityMedium |
CVE-2026-6948Unbounded Memory Allocation in VQLResponse Result-Set Writer | Exploitation statusNot known exploited | FixYes | Published05/03/2026 | SeverityMedium |
CVE-2026-6290Velociraptor Query() Plugin Misapplies Permissions To Orgs | Exploitation statusNot known exploited | FixYes | Published04/15/2026 | SeverityHigh |
CVE-2026-5329Rapid7 Velociraptor Improper Input Validation in Client Message Handler | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityHigh |
CVE-2025-14728Rapid7 Velociraptor Directory Traversal Vulnerability | Exploitation statusNot known exploited | FixYes | Published12/29/2025 | SeverityMedium |
CVE-2025-6264Velociraptor priviledge escalation via UpdateConfig artifact | Exploitation statusNot known exploited | FixYes | Published06/20/2025 | SeverityMedium |
CVE-2025-0914Velociraptor Shell Plugin Prevent_execve Bypass | Exploitation statusNot known exploited | FixYes | Published02/27/2025 | SeverityLow |
CVE-2024-10526Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service | Exploitation statusNot known exploited | FixYes | Published11/07/2024 | SeverityHigh |
CVE-2023-5950Rapid7 Velociraptor Reflected XSS | Exploitation statusNot known exploited | FixYes | Published11/06/2023 | SeverityHigh |
CVE-2023-2226Velociraptor crashes while parsing some malformed PE or OLE files. | Exploitation statusNot known exploited | FixYes | Published04/21/2023 | SeverityLow |
CVE-2023-0290Rapid7 Velociraptor directory traversal in client ID parameter | Exploitation statusNot known exploited | FixYes | Published01/18/2023 | SeverityMedium |
CVE-2023-0242Insufficient permission check in the VQL copy() function | Exploitation statusNot known exploited | FixYes | Published01/18/2023 | SeverityHigh |
CVE-2022-35632XSS in User Interface | Exploitation statusNot confirmed | FixYes | Published07/29/2022 | SeverityUnknown |
CVE-2022-35631Filesystem race on temporary files | Exploitation statusNot confirmed | FixYes | Published07/29/2022 | SeverityUnknown |
CVE-2022-35630Unsafe HTML Injection in Artifact Collection Report | Exploitation statusNot confirmed | FixYes | Published07/29/2022 | SeverityUnknown |
CVE-2022-35629Velociraptor Client ID Spoofing | Exploitation statusNot confirmed | FixYes | Published07/29/2022 | SeverityUnknown |
CVE-2021-3619Rapid7 Velociraptor Notebooks Authenticated Persistent XSS | Exploitation statusNot confirmed | FixYes | Published08/17/2021 | SeverityLow |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan