Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-19584 is a vulnerability in Rapid7 Velociraptor affecting versions from 0 up to but not including 0.77.2. It involves improper neutralization of special elements in a template engine used during notebook backup restoration. A user with NOTEBOOK_EDITOR permission can inject a VQL query into notebook cell content, which is then evaluated with elevated permissions upon backup restoration. Join the discussion | CVE Database V5 | 09/10/2026, 03:00:00 UTC Added: 09/10/2026, 03:07:53 UTC |
0 CVE-2026-19583 is a critical vulnerability in Rapid7 Velociraptor versions before 0.77.2 involving incorrect permission assignment for sensitive artifacts. Specifically, client monitoring artifacts lacked proper permission checks, allowing users with scheduling rights for these artifacts to also schedule highly privileged artifacts like Linux.Sys.BashShell, which enables arbitrary command execution on endpoints. This flaw could lead to unauthorized privilege escalation and control over affected systems. Join the discussion | CVE Database V5 | 09/10/2026, 02:58:11 UTC Added: 09/10/2026, 03:07:53 UTC |
CVE-2026-19200 is a high-severity vulnerability in Rapid7 Velociraptor versions prior to 0.77.2. It involves a missing authorization check in the verify() VQL function, which allows users with NOTEBOOK_EDIT permission to overwrite existing artifacts in the global artifact repository without proper permissions. This flaw could lead to significant confidentiality, integrity, and availability impacts. Join the discussion | CVE Database V5 | 08/24/2026, 03:22:14 UTC Added: 08/24/2026, 03:37:52 UTC |
0 CVE-2026-15371 is a high-severity vulnerability in Rapid7 Velociraptor versions from 0 up to but not including 0.77.2. The web GUI allows users to specify a custom column type as a URL, but it does not restrict URL schemes. This flaw permits an attacker to use a JavaScript scheme, leading to a cross-site scripting (XSS) risk when users click the crafted URL in the GUI. Join the discussion | CVE Database V5 | 08/18/2026, 06:52:28 UTC Added: 08/18/2026, 11:33:14 UTC |
Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes. In particular, a user with read access to the root org can access result sets from child orgs. Join the discussion | CVE Database V5 | 08/12/2026, 09:56:10 UTC Added: 08/12/2026, 10:11:55 UTC |
A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function. Join the discussion | CVE Database V5 | 08/12/2026, 09:49:25 UTC Added: 08/12/2026, 10:11:55 UTC |
The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators"). Join the discussion | CVE Database V5 | 08/12/2026, 09:44:53 UTC Added: 08/12/2026, 10:11:55 UTC |
0 When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory. Join the discussion | CVE Database V5 | 08/12/2026, 09:39:26 UTC Added: 08/12/2026, 10:11:55 UTC |
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role. Join the discussion | CVE Database V5 | 08/12/2026, 04:26:32 UTC Added: 08/12/2026, 12:51:38 UTC |
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover. Join the discussion | CVE Database V5 | 08/11/2026, 15:05:42 UTC Added: 08/11/2026, 15:26:50 UTC |
Showing 1 to 10 of 25 results