Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Velociraptor — Vulnerabilities & Security Advisories 44

All 44 CVE vulnerabilities found in Velociraptor, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data specifically for the Velociraptor product, focusing on a defined weakness type and associated security tags. It collects historical and current security defects reported against this software, covering the full timeline of available advisory records. Readers can use this section to track vendor-published advisories, understand the recurring weakness class, and review the complete vulnerability history of the product.

Vendor: Rapid7

CVE ID Title CVSS Severity Published
CVE-2026-78413 Velociraptor privilege escalation via SysmonLogForward client monitoring artifact CWE-276 5.5 Medium 2026-10-05
CVE-2026-78411 Velociraptor Server Metadata update with Insufficient Permission Check CWE-863 6.5 Medium 2026-10-05
CVE-2026-78412 WatchEvent API streams another organization's live events CWE-639 4.9 Medium 2026-10-05
CVE-2026-77798 Velociraptor Authenticated Denial of Service CWE-833 6.5 Medium 2026-09-24
CVE-2026-77797 Velociraptor Prefetch parser out of bounds CWE-20 3.6 Low 2026-09-24
CVE-2026-19072 Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal CWE-1269 9.9 Critical 2026-09-24
CVE-2026-19584 Velociraptor VQL injection during notebook restore from backup CWE-1336 7.7 High 2026-09-10
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries CWE-732 9.9 Critical 2026-09-10
CVE-2026-19200 Velociraptor Analyst overwrites live built-in artifacts through verify() CWE-862 8.9 High 2026-08-24
CVE-2026-15371 Velociraptor Stored XSS in URL column types CWE-177 8.1 High 2026-08-18
CVE-2026-18652 Velociraptor STACK Type Download Path Bypasses Denied Prefix Check CWE-862 6.5 Medium 2026-08-12
CVE-2026-64951 Velociraptor DoS triggered by Divide by Zero panic CWE-369 3.5 Low 2026-08-12
CVE-2026-64952 Velociraptor Hunt Deletion With Insufficient Permission Check CWE-863 6.5 Medium 2026-08-12
CVE-2026-64955 Velociraptor CSV Formula Injection in Export Pipeline CWE-1236 6.1 Medium 2026-08-12
CVE-2026-64954 Velociraptor collect_client() Permissions Bypass CWE-862 8.2 High 2026-08-12
CVE-2026-18639 Velociraptor OIDC Authenticator susceptible to email spoofing CWE-290 7.3 High 2026-08-11
CVE-2026-18638 Velociraptor server crash via the SetPassword API CWE-476 6.5 Medium 2026-08-11
CVE-2026-18640 Velociraptor directory traversal via the NewNotebook API CWE-22 7.1 High 2026-08-11
CVE-2026-18860 Velociraptor incorrect Org deletion permissions check CWE-280 8.7 High 2026-08-11
CVE-2026-17535 Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes CWE-125 6.2 Medium 2026-08-11
CVE-2026-18636 Velociraptor VFSGetBuffer API path deny list bypass CWE-288 6.8 Medium 2026-08-11
CVE-2026-18635 Velociraptor query plugin allows impersonation in other orgs CWE-863 7.2 High 2026-08-11
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability CWE-290 9.6 Critical 2026-08-11
CVE-2026-18348 Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins CWE-863 4.1 Medium 2026-08-11
CVE-2026-8795 Rapid7 Velociraptor 注入漏洞 CWE-74 7.8 High 2026-06-09
CVE-2026-6863 HTTP Filestore Endpoints Misapply Permissions Across Organizations CWE-863 6.8 Medium 2026-05-06
CVE-2026-7572 Velociraptor EVTX Parser — Process Crash via Crafted .evtx File CWE-193 4.4 Medium 2026-05-06
CVE-2026-7573 GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations CWE-639 5.0 Medium 2026-05-06
CVE-2026-6948 Unbounded Memory Allocation in VQLResponse Result-Set Writer CWE-770 4.9 Medium 2026-05-03
CVE-2026-6290 Velociraptor Query() Plugin Misapplies Permissions To Orgs CWE-863 8.0 High 2026-04-15

All 44 known CVE vulnerabilities affecting Velociraptor with full Chinese analysis, references, and POCs where available.