Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored. Join the discussion | CVE Database V5 | 09/10/2026, 03:00:00 UTC Added: 09/10/2026, 03:07:53 UTC |
0 Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell). Join the discussion | CVE Database V5 | 09/10/2026, 02:58:11 UTC Added: 09/10/2026, 03:07:53 UTC |
CVE-2026-19200 is a high-severity vulnerability in Rapid7 Velociraptor versions prior to 0.77.2. It involves a missing authorization check in the verify() VQL function, which allows users with NOTEBOOK_EDIT permission to overwrite existing artifacts in the global artifact repository without proper permissions. This flaw could lead to significant confidentiality, integrity, and availability impacts. Join the discussion | CVE Database V5 | 08/24/2026, 03:22:14 UTC Added: 08/24/2026, 03:37:52 UTC |
0 CVE-2026-15371 is a high-severity vulnerability in Rapid7 Velociraptor versions from 0 up to but not including 0.77.2. The web GUI allows users to specify a custom column type as a URL, but it does not restrict URL schemes. This flaw permits an attacker to use a JavaScript scheme, leading to a cross-site scripting (XSS) risk when users click the crafted URL in the GUI. Join the discussion | CVE Database V5 | 08/18/2026, 06:52:28 UTC Added: 08/18/2026, 11:33:14 UTC |
Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes. In particular, a user with read access to the root org can access result sets from child orgs. Join the discussion | CVE Database V5 | 08/12/2026, 09:56:10 UTC Added: 08/12/2026, 10:11:55 UTC |
A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function. Join the discussion | CVE Database V5 | 08/12/2026, 09:49:25 UTC Added: 08/12/2026, 10:11:55 UTC |
The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators"). Join the discussion | CVE Database V5 | 08/12/2026, 09:44:53 UTC Added: 08/12/2026, 10:11:55 UTC |
0 When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory. Join the discussion | CVE Database V5 | 08/12/2026, 09:39:26 UTC Added: 08/12/2026, 10:11:55 UTC |
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role. Join the discussion | CVE Database V5 | 08/12/2026, 04:26:32 UTC Added: 08/12/2026, 12:51:38 UTC |
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover. Join the discussion | CVE Database V5 | 08/11/2026, 15:05:42 UTC Added: 08/11/2026, 15:26:50 UTC |
Showing 1 to 10 of 25 results