VendorsRapid7velociraptorall versions
Vulnerabilities

Rapid7 Velociraptor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-6290
Velociraptor Query() Plugin Misapplies Permissions To Orgs
Published 2026-04-15 · Analyzed
9.1EPSS 0.004
CVE-2023-0242
Insufficient permission check in the VQL copy() function
Published 2023-01-18 · Modified
8.8EPSS 0.005
CVE-2023-5950
Rapid7 Velociraptor Reflected XSS
Published 2023-11-06 · Modified
8.6EPSS 0.005
CVE-2026-5329
Rapid7 Velociraptor Improper Input Validation in Client Message Handler
Published 2026-04-09 · Analyzed
8.5EPSS 0.006
CVE-2026-7573
GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations
Published 2026-05-06 · Analyzed
7.7EPSS 0.003
CVE-2025-14728
Rapid7 Velociraptor Directory Traversal Vulnerability
Published 2025-12-29 · Analyzed
6.8EPSS 0.006
CVE-2022-35630
Unsafe HTML Injection in Artifact Collection Report
Published 2022-07-29 · Modified
6.1EPSS 0.005
CVE-2025-6264
Velociraptor priviledge escalation via UpdateConfig artifact
Published 2025-06-20 · Modified
5.5EPSS 0.010
CVE-2022-35631
Filesystem race on temporary files
Published 2022-07-29 · Modified
5.5EPSS 0.002
CVE-2026-7572
Velociraptor EVTX Parser — Process Crash via Crafted .evtx File
Published 2026-05-06 · Analyzed
5.5EPSS 0.001
CVE-2022-35629
Velociraptor Client ID Spoofing
Published 2022-07-29 · Modified
5.4EPSS 0.005
CVE-2023-2226
Velociraptor crashes while parsing some malformed PE or OLE files.
Published 2023-04-21 · Modified
5.3EPSS 0.004
CVE-2021-3619
Rapid7 Velociraptor Notebooks Authenticated Persistent XSS
Published 2021-08-17 · Modified
4.8EPSS 0.006
CVE-2022-35632
XSS in User Interface
Published 2022-07-29 · Modified
4.8EPSS 0.005
CVE-2023-0290
Rapid7 Velociraptor directory traversal in client ID parameter
Published 2023-01-18 · Modified
4.3EPSS 0.007