« Volver al listado

Rapid7

Rapid7 Velociraptor: vulnerabilidades y CVE

Rapid7 Velociraptor tiene 17 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses6
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-8795Alta (7.8)0.21%—9 jun 2026
A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML…
CVE-2026-7573Alta (7.7)0.30%—6 may 2026
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and…
CVE-2026-7572Media (5.5)0.14%—6 may 2026
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS)…
CVE-2026-6290Crítica (9.1)0.39%—15 abr 2026
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use…
CVE-2026-5329Media (6.5)0.64%—9 abr 2026
Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote…
CVE-2025-14728Media (6.8)0.56%—29 dic 2025
Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only…
CVE-2025-6264Media (5.5)1.0%—20 jun 2025
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact,…
CVE-2024-10526Alta (8.6)0.17%—7 nov 2024
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are…
CVE-2023-5950Media (6.1)0.46%—6 nov 2023
Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inject JS into the error path, potentially leading to unauthorized…
CVE-2023-2226Media (5.3)0.38%—21 abr 2023
Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor during parsing of maliciously malformed files. For this attack to…
CVE-2023-0290Media (4.3)0.74%—18 ene 2023
Rapid7 Velociraptor did not properly sanitize the client ID parameter to the CreateCollection API, allowing a directory traversal in where the collection task could be written. It was possible to provide a client id of…
CVE-2023-0242Alta (8.8)0.54%—18 ene 2023
Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on the server including writing arbitrary files. However, lower privilege…
CVE-2022-35632Media (4.8)0.47%—29 jul 2022
The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS).…
CVE-2022-35631Media (5.5)0.23%—29 jul 2022
On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was…
CVE-2022-35630Media (6.1)0.49%—29 jul 2022
A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2.
CVE-2022-35629Media (5.4)0.45%—29 jul 2022
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another…
CVE-2021-3619Media (4.8)0.58%—22 jul 2021
Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution2
  2. T1210 Exploitation of Remote Services2
  3. T1059 Command and Scripting Interpreter1
  4. T1078 Valid Accounts1
  5. T1222 File and Directory Permissions Modification1
  6. T1552.007 Container API1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Rapid7