Skip to content
Noroxi

Splunk records

371 published records for vendor splunk.

All records

371 records
  • Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    splunk · splunkJun 10, 2026

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    openssl · opensslApr 7, 2014

  • CVE-2023-46214
    62This week

    Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing

    HighCVSS 8.8WeaponizedEPSS 89%

    splunk · cloudNov 16, 2023

  • ‘edit_user’ Capability Privilege Escalation

    HighCVSS 8.8WeaponizedEPSS 79%

    splunk · splunkJun 1, 2023

  • Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demon

    MediumCVSS 5.3WeaponizedEPSS 98%

    splunk · splunkJun 8, 2018

  • curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session t

    HighCVSS 8.1No exploitEPSS 60%

    haxx · curlJun 11, 2021

  • Path Traversal in Splunk App for Lookup File Editing

    HighCVSS 8.1No exploitEPSS 43%

    splunk · splunkJun 1, 2023

  • Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway

    HighCVSS 8.8Proof of conceptEPSS 32%

    splunk · splunkJun 10, 2026

  • When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a ren

    CriticalCVSS 9.8No exploitEPSS 8%

    haxx · curlJul 7, 2022

  • Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a

    HighCVSS 8.8No exploitEPSS 18%

    google · chromeAug 3, 2021

  • When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when th

    CriticalCVSS 9.8No exploitEPSS 4%

    haxx · curlDec 5, 2022

  • Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and

    CriticalCVSS 9.8No exploitEPSS 4%

    splunk · splunkJan 10, 2017

  • There's a flaw in lz4.

    CriticalCVSS 9.8No exploitEPSS 3%

    lz4 project · lz4Jun 2, 2021

  • Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12,

    CriticalCVSS 9.8No exploitEPSS 3%

    splunk · splunkNov 29, 2017

  • In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th

    CriticalCVSS 9.8No exploitEPSS 2%

    libarchive · libarchiveNov 21, 2022

  • Splunk Enterprise deployment servers allow client publishing of forwarder bundles

    CriticalCVSS 10.0No exploitEPSS 1%

    splunk · splunkJun 15, 2022

  • Remote Code Execution through dashboard PDF generation component in Splunk Enterprise

    HighCVSS 8.8WeaponizedEPSS 14%

    splunk · splunkNov 3, 2022

  • CVE-2011-4644
    39Monitor

    Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentio

    CriticalCVSS 9.3Proof of conceptEPSS 8%

    splunk · splunkJan 3, 2012

  • Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validation

    CriticalCVSS 9.8No exploitEPSS 0%

    splunk · splunkAug 16, 2022

  • Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream

    CriticalCVSS 9.9No exploitEPSS 0%

    splunk · splunk app for streamJun 1, 2023

  • When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed

    CriticalCVSS 9.1No exploitEPSS 7%

    haxx · libcurlSep 23, 2021

  • CVE-2013-6771
    38Monitor

    Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .

    CriticalCVSS 9.3No exploitEPSS 5%

    splunk · splunkAug 7, 2014

  • Reflected Cross-Site Scripting via the radio template in Splunk Enterprise

    MediumCVSS 6.1No exploitEPSS 43%

    splunk · splunkNov 4, 2022

  • SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a

    HighCVSS 7.5Proof of conceptEPSS 23%

    sqlite · sqliteAug 3, 2022

  • Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprise

    HighCVSS 8.0No exploitEPSS 16%

    splunk · splunkMar 26, 2025