Splunk records
371 published records for vendor splunk.
Researcher profile
- Entered KEV
- 2 · 0.5%
- Weaponized
- 8 · 2.2%
- Pre-auth RCE
- 7
- With a fix record
- 16.2%
- Median publish → KEV
- 1479 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')53
- CWE-20 Improper Input Validation31
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor29
- CWE-284 Improper Access Control17
- CWE-862 Missing Authorization14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')13
The weakness classes this vendor ships most often: where to look.
CWEAll records
371 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2026-20253Weaponized | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprisesplunk · splunk · CWE-306 | Critical9.8 | KEV | 96.9% | Jun 10, 2026 |
90Now | CVE-2014-0160Weaponized | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | High7.5 | KEV | 100.0% | Apr 7, 2014 |
62This week | CVE-2023-46214Weaponized | Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsingsplunk · cloud · CWE-91 | High8.8 | — | 89.2% | Nov 16, 2023 |
59Plan | CVE-2023-32707Weaponized | ‘edit_user’ Capability Privilege Escalationsplunk · splunk · CWE-285 | High8.8 | — | 79.0% | Jun 1, 2023 |
50Plan | CVE-2018-11409Weaponized | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonsplunk · splunk · CWE-200 | Medium5.3 | — | 98.3% | Jun 8, 2018 |
50Plan | CVE-2021-22901No exploit | curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session thaxx · curl · CWE-416 | High8.1 | — | 60.1% | Jun 11, 2021 |
45Plan | CVE-2023-32714No exploit | Path Traversal in Splunk App for Lookup File Editingsplunk · splunk · CWE-35 | High8.1 | — | 42.8% | Jun 1, 2023 |
45Plan | CVE-2026-20251Proof of concept | Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gatewaysplunk · splunk · CWE-502 | High8.8 | — | 32.2% | Jun 10, 2026 |
41Plan | CVE-2022-32207No exploit | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a renhaxx · curl · CWE-840 | Critical9.8 | — | 7.7% | Jul 7, 2022 |
40Plan | CVE-2021-30560No exploit | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a google · chrome · CWE-416 | High8.8 | — | 17.6% | Aug 3, 2021 |
40Plan | CVE-2022-32221No exploit | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when thhaxx · curl · CWE-200 | Critical9.8 | — | 4.4% | Dec 5, 2022 |
40Plan | CVE-2016-10126No exploit | Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and splunk · splunk · CWE-264 | Critical9.8 | — | 4.0% | Jan 10, 2017 |
40Plan | CVE-2021-3520No exploit | There's a flaw in lz4.lz4 project · lz4 · CWE-190 | Critical9.8 | — | 3.2% | Jun 2, 2021 |
40Plan | CVE-2017-17067No exploit | Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12,splunk · splunk · CWE-863 | Critical9.8 | — | 3.0% | Nov 29, 2017 |
40Plan | CVE-2022-36227No exploit | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if thlibarchive · libarchive · CWE-476 | Critical9.8 | — | 2.4% | Nov 21, 2022 |
40Plan | CVE-2022-32158No exploit | Splunk Enterprise deployment servers allow client publishing of forwarder bundlessplunk · splunk · CWE-284 | Critical10.0 | — | 1.4% | Jun 15, 2022 |
39Monitor | CVE-2022-43571Weaponized | Remote Code Execution through dashboard PDF generation component in Splunk Enterprisesplunk · splunk · CWE-94 | High8.8 | — | 13.8% | Nov 3, 2022 |
39Monitor | CVE-2011-4644Proof of concept | Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentiosplunk · splunk · CWE-287 | Critical9.3 | — | 7.5% | Jan 3, 2012 |
39Monitor | CVE-2022-37437No exploit | Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validationsplunk · splunk · CWE-295 | Critical9.8 | — | 0.4% | Aug 16, 2022 |
39Monitor | CVE-2023-32713No exploit | Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Streamsplunk · splunk app for stream · CWE-269 | Critical9.9 | — | 0.3% | Jun 1, 2023 |
38Monitor | CVE-2021-22945No exploit | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freedhaxx · libcurl · CWE-415 | Critical9.1 | — | 6.7% | Sep 23, 2021 |
38Monitor | CVE-2013-6771No exploit | Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .splunk · splunk · CWE-22 | Critical9.3 | — | 4.8% | Aug 7, 2014 |
37Monitor | CVE-2022-43568No exploit | Reflected Cross-Site Scripting via the radio template in Splunk Enterprisesplunk · splunk · CWE-79 | Medium6.1 | — | 42.8% | Nov 4, 2022 |
37Monitor | CVE-2022-35737Proof of concept | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to asqlite · sqlite · CWE-129 | High7.5 | — | 22.8% | Aug 3, 2022 |
37Monitor | CVE-2025-20229No exploit | Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprisesplunk · splunk · CWE-284 | High8.0 | — | 16.0% | Mar 26, 2025 |
- CVE-2026-2025398Now
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
CriticalCVSS 9.8KEVWeaponizedEPSS 97%splunk · splunkJun 10, 2026
- CVE-2014-016090Now
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
HighCVSS 7.5KEVWeaponizedEPSS 100%openssl · opensslApr 7, 2014
- CVE-2023-4621462This week
Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
HighCVSS 8.8WeaponizedEPSS 89%splunk · cloudNov 16, 2023
- CVE-2023-3270759Plan
‘edit_user’ Capability Privilege Escalation
HighCVSS 8.8WeaponizedEPSS 79%splunk · splunkJun 1, 2023
- CVE-2018-1140950Plan
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demon
MediumCVSS 5.3WeaponizedEPSS 98%splunk · splunkJun 8, 2018
- CVE-2021-2290150Plan
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session t
HighCVSS 8.1No exploitEPSS 60%haxx · curlJun 11, 2021
- CVE-2023-3271445Plan
Path Traversal in Splunk App for Lookup File Editing
HighCVSS 8.1No exploitEPSS 43%splunk · splunkJun 1, 2023
- CVE-2026-2025145Plan
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
HighCVSS 8.8Proof of conceptEPSS 32%splunk · splunkJun 10, 2026
- CVE-2022-3220741Plan
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a ren
CriticalCVSS 9.8No exploitEPSS 8%haxx · curlJul 7, 2022
- CVE-2021-3056040Plan
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a
HighCVSS 8.8No exploitEPSS 18%google · chromeAug 3, 2021
- CVE-2022-3222140Plan
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when th
CriticalCVSS 9.8No exploitEPSS 4%haxx · curlDec 5, 2022
- CVE-2016-1012640Plan
Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and
CriticalCVSS 9.8No exploitEPSS 4%splunk · splunkJan 10, 2017
- CVE-2021-352040Plan
There's a flaw in lz4.
CriticalCVSS 9.8No exploitEPSS 3%lz4 project · lz4Jun 2, 2021
- CVE-2017-1706740Plan
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12,
CriticalCVSS 9.8No exploitEPSS 3%splunk · splunkNov 29, 2017
- CVE-2022-3622740Plan
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th
CriticalCVSS 9.8No exploitEPSS 2%libarchive · libarchiveNov 21, 2022
- CVE-2022-3215840Plan
Splunk Enterprise deployment servers allow client publishing of forwarder bundles
CriticalCVSS 10.0No exploitEPSS 1%splunk · splunkJun 15, 2022
- CVE-2022-4357139Monitor
Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
HighCVSS 8.8WeaponizedEPSS 14%splunk · splunkNov 3, 2022
- CVE-2011-464439Monitor
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentio
CriticalCVSS 9.3Proof of conceptEPSS 8%splunk · splunkJan 3, 2012
- CVE-2022-3743739Monitor
Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validation
CriticalCVSS 9.8No exploitEPSS 0%splunk · splunkAug 16, 2022
- CVE-2023-3271339Monitor
Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream
CriticalCVSS 9.9No exploitEPSS 0%splunk · splunk app for streamJun 1, 2023
- CVE-2021-2294538Monitor
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed
CriticalCVSS 9.1No exploitEPSS 7%haxx · libcurlSep 23, 2021
- CVE-2013-677138Monitor
Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .
CriticalCVSS 9.3No exploitEPSS 5%splunk · splunkAug 7, 2014
- CVE-2022-4356837Monitor
Reflected Cross-Site Scripting via the radio template in Splunk Enterprise
MediumCVSS 6.1No exploitEPSS 43%splunk · splunkNov 4, 2022
- CVE-2022-3573737Monitor
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a
HighCVSS 7.5Proof of conceptEPSS 23%sqlite · sqliteAug 3, 2022
- CVE-2025-2022937Monitor
Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprise
HighCVSS 8.0No exploitEPSS 16%splunk · splunkMar 26, 2025