Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.16% | — | VelociraptorAI | 5/10/2026 | 6/10/2026 | Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The… | |
| Pendiente de análisis | Media (6.5) | 0.17% | — | Velocidex VelociraptorAI | 5/10/2026 | 6/10/2026 | Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin. | |
| Pendiente de análisis | Media (4.9) | 0.22% | — | VelociraptorAI | 5/10/2026 | 6/10/2026 | Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access. | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | VelociraptorAI | 24/9/2026 | 24/9/2026 | Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module. | |
| Pendiente de análisis | Baja (3.6) | 0.10% | — | VelociraptorAI | 24/9/2026 | 24/9/2026 | Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files. | |
| Pendiente de análisis | Crítica (9.9) | 0.40% | — | VelociraptorAI | 24/9/2026 | 25/9/2026 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt… | |
| Pendiente de análisis | Alta (7.7) | 0.19% | — | VelociraptorAI | 10/9/2026 | 11/9/2026 | Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be… | |
| Pendiente de análisis | Crítica (9.9) | 0.60% | — | VelociraptorAI | 10/9/2026 | 11/9/2026 | Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally… | |
| Pendiente de análisis | Alta (8.9) | 0.23% | — | VelociraptorAI | 24/8/2026 | 28/8/2026 | The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions. The attacker need only have the… | |
| Pendiente de análisis | Alta (8.1) | 0.37% | — | VelociraptorAI | 18/8/2026 | 28/8/2026 | Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS. | |
| Pendiente de análisis | Media (6.1) | 0.36% | — | Microsoft ExcelAIVelociraptorAI | 12/8/2026 | 28/8/2026 | When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the… | |
| Pendiente de análisis | Media (6.5) | 0.30% | — | VelociraptorAI | 12/8/2026 | 28/8/2026 | The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators"). | |
| Pendiente de análisis | Baja (3.5) | 0.28% | — | VelociraptorAI | 12/8/2026 | 28/8/2026 | A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function. | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | VelociraptorAI | 12/8/2026 | 28/8/2026 | Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes. In particular, a user with read access… | |
| Pendiente de análisis | Alta (8.2) | 0.31% | — | VelociraptorAI | 12/8/2026 | 28/8/2026 | Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL… | |
| Pendiente de análisis | Alta (7.3) | 0.39% | — | VelociraptorAI | 11/8/2026 | 28/8/2026 | When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | Velocidex VelociraptorAI | 11/8/2026 | 28/8/2026 | Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist. | |
| Pendiente de análisis | Alta (8.7) | 0.44% | — | VelociraptorAI | 11/8/2026 | 28/8/2026 | Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.… | |
| Pendiente de análisis | Media (6.8) | 0.40% | — | VelociraptorAI | 11/8/2026 | 28/8/2026 | The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied… | |
| Pendiente de análisis | Alta (7.2) | 0.46% | — | VelociraptorAI | 11/8/2026 | 28/8/2026 | Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.77.2 evaluate this permission against… | |
| Pendiente de análisis | Media (6.2) | 0.16% | — | VelociraptorAI | 11/8/2026 | 28/8/2026 | Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications… | |
| Pendiente de análisis | Media (4.1) | 0.34% | — | VelociraptorAI | 11/8/2026 | 28/8/2026 | Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via… | |
| Pendiente de análisis | Alta (7.8) | 0.21% | — | Rapid7 VelociraptorAI | 9/6/2026 | 23/7/2026 | A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML template via Go's text/template without escaping. An attacker providing a crafted collection ZIP can… | |
| Pendiente de análisis | Media (6.8) | 0.40% | — | VelociraptorAI | 6/5/2026 | 17/6/2026 | Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with only the reader role in the root organization (the lowest authenticated role, holding only READ_RESULTS permission ) can issue a single authenticated HTTP GET that can read any files from other orgs -… | |
| Analizada | Alta (7.7) | 0.30% | — | Rapid7 Velociraptor | 6/5/2026 | 24/7/2026 | An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a… |