VYPR

Vendor CVEs

Splunk

All CVEs

395 total · sorted by risk
  • CVE-2010-3322HigSep 14, 2010
    risk 0.57cvss 8.8epss 0.01

    The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.

  • CVE-2023-4571HigAug 30, 2023
    risk 0.56cvss 8.6epss 0.00

    In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Institute (ANSI) escape codes into Splunk ITSI log files that, when a vulnerable terminal application reads them, can run malicious…

  • CVE-2023-3997HigJul 31, 2023
    risk 0.56cvss 8.6epss 0.00

    Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal…

  • CVE-2023-32714HigJun 1, 2023
    risk 0.56cvss 8.1epss 0.43

    In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.

  • CVE-2023-32712HigJun 1, 2023
    risk 0.56cvss 8.6epss 0.00

    In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files that, when a vulnerable terminal application reads them, can potentially, at worst, result in possible code…

  • CVE-2023-40598HigAug 30, 2023
    risk 0.55cvss 8.5epss 0.01

    In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can…

  • CVE-2023-40592HigAug 30, 2023
    risk 0.55cvss 8.4epss 0.01

    In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scripting (XSS) on the “/app/search/table” web endpoint. Exploitation of this vulnerability can lead to the execution of…

  • CVE-2026-76394HigAug 19, 2026
    risk 0.54cvss 8.3epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The…

  • CVE-2026-76391HigAug 19, 2026
    risk 0.54cvss 8.3epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run…

  • CVE-2026-76402HigAug 19, 2026
    risk 0.53cvss 8.2epss 0.00

    In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the…

  • CVE-2026-76399HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect…

  • CVE-2026-76397HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted…

  • CVE-2026-76388HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all…

  • CVE-2026-76387HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data…

  • CVE-2026-76356HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation…

  • CVE-2026-76354HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API request that deletes or temporarily…

  • CVE-2026-76338HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity, and disrupt service…

  • CVE-2026-76331HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject Search Processing Language (SPL) into saved-search dispatch requests. This could allow for unauthorized access to all relevant data…

  • CVE-2025-20229HigMar 26, 2025
    risk 0.53cvss 8.0epss 0.16

    In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution…

  • CVE-2024-36997HigJul 1, 2024
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could…

  • CVE-2024-29946HigMar 27, 2024
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by…

  • CVE-2023-46230HigJan 30, 2024
    risk 0.53cvss 8.2epss 0.00

    In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.

  • CVE-2023-22939HigFeb 14, 2023
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only…

  • CVE-2023-22935HigFeb 14, 2023
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their…

  • CVE-2022-43565HigNov 4, 2022
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The…

  • CVE-2022-43563HigNov 4, 2022
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires…

  • CVE-2022-42915HigOct 29, 2022
    risk 0.53cvss 8.1epss 0.03

    curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might…

  • CVE-2022-32156HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configure TLS host name validation…

  • CVE-2022-32153HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates…

  • CVE-2022-32152HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates…

  • CVE-2022-27778HigJun 2, 2022
    risk 0.53cvss 8.1epss 0.04

    A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

  • CVE-2021-26253HigMay 6, 2022
    risk 0.53cvss 8.1epss 0.01

    A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and does not impact or…

  • CVE-2019-5729HigMar 21, 2019
    risk 0.53cvss 8.1epss 0.01

    Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.

  • CVE-2025-20387HigDec 3, 2025
    risk 0.52cvss 8.0epss 0.00

    In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory. This lets…

  • CVE-2025-20386HigDec 3, 2025
    risk 0.52cvss 8.0epss 0.00

    In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets non-administrator…

  • CVE-2025-20298HigJun 2, 2025
    risk 0.52cvss 8.0epss 0.00

    In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program…

  • CVE-2024-45731HigOct 14, 2024
    risk 0.52cvss 8.0epss 0.01

    In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk…

  • CVE-2024-36983HigJul 1, 2024
    risk 0.52cvss 8.0epss 0.01

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal…

  • CVE-2023-22933HigFeb 14, 2023
    risk 0.52cvss 8.0epss 0.01

    In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) View through the ‘layoutPanel’ attribute in the ‘module’ tag’.

  • CVE-2022-43569HigNov 4, 2022
    risk 0.52cvss 8.0epss 0.01

    In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.

  • CVE-2023-40597HigAug 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.

  • CVE-2023-32713HigJun 1, 2023
    risk 0.51cvss 7.8epss 0.00

    In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user.

  • CVE-2020-8177HigDec 14, 2020
    risk 0.51cvss 7.8epss 0.01

    curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

  • CVE-2013-6773HigJan 23, 2020
    risk 0.51cvss 7.8epss 0.00

    Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges

  • CVE-2026-76344HigAug 19, 2026
    risk 0.50cvss 7.7epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Representational State Transfer…

  • CVE-2024-36991HigJul 1, 2024
    risk 0.50cvss 7.5epss 0.13

    In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

  • CVE-2023-32706HigJun 1, 2023
    risk 0.50cvss 7.7epss 0.01

    On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon.

  • CVE-2022-43551HigDec 23, 2022
    risk 0.50cvss 7.5epss 0.17

    A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS…

  • CVE-2022-35737HigAug 3, 2022
    risk 0.50cvss 7.5epss 0.21

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

  • CVE-2021-22926HigAug 5, 2021
    risk 0.50cvss 7.5epss 0.10

    libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask…

Page 2 of 8