Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.14% | — | Rapid7 Velociraptor | 6/5/2026 | 24/7/2026 | An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx VQL plugin. | |
| Pendiente de análisis | Media (4.9) | 0.44% | — | Velocidex VelociraptorAI | 4/5/2026 | 17/6/2026 | Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel. | |
| Analizada | Crítica (9.1) | 0.39% | — | Rapid7 Velociraptor | 15/4/2026 | 17/6/2026 | Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which they may not have… | |
| Analizada | Media (6.5) | 0.64% | — | Rapid7 Velociraptor | 9/4/2026 | 17/6/2026 | Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring message with a… | |
| Analizada | Media (6.8) | 0.56% | — | Rapid7 Velociraptor | 29/12/2025 | 30/9/2026 | Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficient sanitization of… | |
| Modificada | Media (5.5) | 1.0% | 💥 PoC | Rapid7 Velociraptor | 20/6/2025 | 17/6/2026 | Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The… | |
| Aplazada | Baja (3.8) | 0.23% | — | Velocidex VelociraptorAI | 27/2/2025 | 17/6/2026 | An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments where this was explicitly forbidden by configuring the prevent_execve flag in the configuration file. This setting is not usually recommended and is… | |
| Modificada | Media (5.5) | 0.32% | — | Librdf Raptor RDF Syntax Library | 10/1/2025 | 17/6/2026 | In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path(). | |
| Modificada | Media (5.5) | 0.29% | — | Librdf Raptor RDF Syntax Library | 10/1/2025 | 17/6/2026 | In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal(). | |
| Aplazada | Alta (8.6) | 0.17% | — | Rapid7 VelociraptorAI | 7/11/2024 | 17/6/2026 | Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptor's files. By… | |
| Aplazada | Media (6.5) | 0.27% | — | Faceleg Raptor EditorAI | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faceleg Raptor Editor wp-raptor allows DOM-Based XSS.This issue affects Raptor Editor: from n/a through <= 1.0.20. | |
| Modificada | Media (6.1) | 0.45% | — | Zediious Raptor-web | 28/11/2023 | 17/6/2026 | raptor-web is a CMS for game server communities that can be used to host information and keep track of players. In version 0.4.4 of raptor-web, it is possible to craft a malicious URL that will result in a reflected cross-site scripting vulnerability. A user controlled URL parameter is loaded into an internal template… | |
| Modificada | Media (6.1) | 0.46% | — | Rapid7 Velociraptor | 6/11/2023 | 17/6/2026 | Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inject JS into the error path, potentially leading to unauthorized execution of scripts within a user's web browser. This vulnerability is fixed in version 0.7.0-04 and a… | |
| Modificada | Media (5.3) | 0.38% | — | Rapid7 Velociraptor | 21/4/2023 | 17/6/2026 | Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor during parsing of maliciously malformed files. For this attack to succeed, the attacker needs to be able to introduce malicious files to the system at the same time that… | |
| Modificada | Media (4.3) | 0.74% | — | Rapid7 Velociraptor | 18/1/2023 | 17/6/2026 | Rapid7 Velociraptor did not properly sanitize the client ID parameter to the CreateCollection API, allowing a directory traversal in where the collection task could be written. It was possible to provide a client id of "../clients/server" to schedule the collection for the server (as a server artifact), but only… | |
| Modificada | Alta (8.8) | 0.54% | — | Rapid7 Velociraptor | 18/1/2023 | 17/6/2026 | Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on the server including writing arbitrary files. However, lower privilege users are generally forbidden from writing or modifying files on the server. The VQL copy() function… | |
| Modificada | Media (4.8) | 0.47% | — | Rapid7 Velociraptor | 29/7/2022 | 17/6/2026 | The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2. | |
| Modificada | Media (5.5) | 0.23% | — | Rapid7 Velociraptor | 29/7/2022 | 17/6/2026 | On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2. | |
| Modificada | Media (6.1) | 0.49% | — | Rapid7 Velociraptor | 29/7/2022 | 17/6/2026 | A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2. | |
| Modificada | Media (5.4) | 0.45% | — | Rapid7 Velociraptor | 29/7/2022 | 17/6/2026 | Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2. | |
| Modificada | Media (4.8) | 0.58% | — | Rapid7 Velociraptor | 22/7/2021 | 17/6/2026 | Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a malicious upload. This issue was fixed in version 0.6.0. Note that login rights to Velociraptor is nearly… | |
| Modificada | Media (6.5) | 2.1% | — | Librdf Raptor RDF Syntax LibraryFedoraproject FedoraDebian Linux | 13/5/2021 | 17/6/2026 | A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common. | |
| Modificada | Alta (7.1) | 3.1% | — | Librdf Raptor RDF Syntax LibraryDebian LinuxFedoraproject Fedora | 6/11/2020 | 17/6/2026 | raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml). | |
| Modificada | Media (6.5) | 14% | — | Librdf RaptorLibreofficeApache OpenofficeFedoraproject Fedora+9 | 17/6/2012 | 16/6/2026 | Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document. | |
| Modificada | Media (5) | 1.6% | — | Symantec Enterprise FirewallSymantec VelociraptorSymantec Gateway Security 5300Symantec Gateway Security 5400 | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites. |