Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module. Join the discussion | CVE Database V5 | 09/24/2026, 13:50:40 UTC Added: 09/24/2026, 14:03:47 UTC |
Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files. Join the discussion | CVE Database V5 | 09/24/2026, 13:49:41 UTC Added: 09/24/2026, 14:03:47 UTC |
0 Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hunt bypassing any ACL checks that would normally be applied. This flaw can then be escalated to allow the "investigator" user to run arbitrary VQL statements as an administrator user on the Velociraptor server. Join the discussion | CVE Database V5 | 09/24/2026, 12:52:51 UTC Added: 09/24/2026, 13:03:29 UTC |
0 CVE-2026-19584 is a vulnerability in Rapid7 Velociraptor affecting versions from 0 up to but not including 0.77.2. It involves improper neutralization of special elements in a template engine used during notebook backup restoration. A user with NOTEBOOK_EDITOR permission can inject a VQL query into notebook cell content, which is then evaluated with elevated permissions upon backup restoration. Join the discussion | CVE Database V5 | 09/10/2026, 03:00:00 UTC Added: 09/10/2026, 03:07:53 UTC |
0 CVE-2026-19583 is a critical vulnerability in Rapid7 Velociraptor versions before 0.77.2 involving incorrect permission assignment for sensitive artifacts. Specifically, client monitoring artifacts lacked proper permission checks, allowing users with scheduling rights for these artifacts to also schedule highly privileged artifacts like Linux.Sys.BashShell, which enables arbitrary command execution on endpoints. This flaw could lead to unauthorized privilege escalation and control over affected systems. Join the discussion | CVE Database V5 | 09/10/2026, 02:58:11 UTC Added: 09/10/2026, 03:07:53 UTC |
CVE-2026-19200 is a high-severity vulnerability in Rapid7 Velociraptor versions prior to 0.77.2. It involves a missing authorization check in the verify() VQL function, which allows users with NOTEBOOK_EDIT permission to overwrite existing artifacts in the global artifact repository without proper permissions. This flaw could lead to significant confidentiality, integrity, and availability impacts. Join the discussion | CVE Database V5 | 08/24/2026, 03:22:14 UTC Added: 08/24/2026, 03:37:52 UTC |
0 CVE-2026-15371 is a high-severity vulnerability in Rapid7 Velociraptor versions from 0 up to but not including 0.77.2. The web GUI allows users to specify a custom column type as a URL, but it does not restrict URL schemes. This flaw permits an attacker to use a JavaScript scheme, leading to a cross-site scripting (XSS) risk when users click the crafted URL in the GUI. Join the discussion | CVE Database V5 | 08/18/2026, 06:52:28 UTC Added: 08/18/2026, 11:33:14 UTC |
Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes. In particular, a user with read access to the root org can access result sets from child orgs. Join the discussion | CVE Database V5 | 08/12/2026, 09:56:10 UTC Added: 08/12/2026, 10:11:55 UTC |
A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function. Join the discussion | CVE Database V5 | 08/12/2026, 09:49:25 UTC Added: 08/12/2026, 10:11:55 UTC |
The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators"). Join the discussion | CVE Database V5 | 08/12/2026, 09:44:53 UTC Added: 08/12/2026, 10:11:55 UTC |
Showing 1 to 10 of 29 results