Записи Splunk
371 опубликованных записей вендора splunk.
Профиль для исследователя
- Попали в KEV
- 2 · 0,5 %
- С эксплойтом
- 8 · 2,2 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 16,2 %
- Медиана: публикация → KEV
- 1479 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')53
- CWE-20 Improper Input Validation31
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor29
- CWE-284 Improper Access Control17
- CWE-862 Missing Authorization14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')13
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
371 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2026-20253Готовый эксплойт | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprisesplunk · splunk · CWE-306 | Критическая9,8 | KEV | 96,9 % | 10 июн. 2026 г. |
90Срочно | CVE-2014-0160Готовый эксплойт | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Высокая7,5 | KEV | 100,0 % | 7 апр. 2014 г. |
62На этой неделе | CVE-2023-46214Готовый эксплойт | Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsingsplunk · cloud · CWE-91 | Высокая8,8 | — | 89,2 % | 16 нояб. 2023 г. |
59В плане | CVE-2023-32707Готовый эксплойт | ‘edit_user’ Capability Privilege Escalationsplunk · splunk · CWE-285 | Высокая8,8 | — | 79,0 % | 1 июн. 2023 г. |
50В плане | CVE-2018-11409Готовый эксплойт | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonsplunk · splunk · CWE-200 | Средняя5,3 | — | 98,3 % | 8 июн. 2018 г. |
50В плане | CVE-2021-22901Эксплойта нет | curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session thaxx · curl · CWE-416 | Высокая8,1 | — | 60,1 % | 11 июн. 2021 г. |
45В плане | CVE-2023-32714Эксплойта нет | Path Traversal in Splunk App for Lookup File Editingsplunk · splunk · CWE-35 | Высокая8,1 | — | 42,8 % | 1 июн. 2023 г. |
45В плане | CVE-2026-20251Proof of concept | Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gatewaysplunk · splunk · CWE-502 | Высокая8,8 | — | 32,2 % | 10 июн. 2026 г. |
41В плане | CVE-2022-32207Эксплойта нет | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a renhaxx · curl · CWE-840 | Критическая9,8 | — | 7,7 % | 7 июл. 2022 г. |
40В плане | CVE-2021-30560Эксплойта нет | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a google · chrome · CWE-416 | Высокая8,8 | — | 17,6 % | 3 авг. 2021 г. |
40В плане | CVE-2022-32221Эксплойта нет | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when thhaxx · curl · CWE-200 | Критическая9,8 | — | 4,4 % | 5 дек. 2022 г. |
40В плане | CVE-2016-10126Эксплойта нет | Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and splunk · splunk · CWE-264 | Критическая9,8 | — | 4,0 % | 10 янв. 2017 г. |
40В плане | CVE-2021-3520Эксплойта нет | There's a flaw in lz4.lz4 project · lz4 · CWE-190 | Критическая9,8 | — | 3,2 % | 2 июн. 2021 г. |
40В плане | CVE-2017-17067Эксплойта нет | Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12,splunk · splunk · CWE-863 | Критическая9,8 | — | 3,0 % | 29 нояб. 2017 г. |
40В плане | CVE-2022-36227Эксплойта нет | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if thlibarchive · libarchive · CWE-476 | Критическая9,8 | — | 2,4 % | 21 нояб. 2022 г. |
40В плане | CVE-2022-32158Эксплойта нет | Splunk Enterprise deployment servers allow client publishing of forwarder bundlessplunk · splunk · CWE-284 | Критическая10,0 | — | 1,4 % | 15 июн. 2022 г. |
39Наблюдать | CVE-2022-43571Готовый эксплойт | Remote Code Execution through dashboard PDF generation component in Splunk Enterprisesplunk · splunk · CWE-94 | Высокая8,8 | — | 13,8 % | 3 нояб. 2022 г. |
39Наблюдать | CVE-2011-4644Proof of concept | Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentiosplunk · splunk · CWE-287 | Критическая9,3 | — | 7,5 % | 3 янв. 2012 г. |
39Наблюдать | CVE-2022-37437Эксплойта нет | Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validationsplunk · splunk · CWE-295 | Критическая9,8 | — | 0,4 % | 16 авг. 2022 г. |
39Наблюдать | CVE-2023-32713Эксплойта нет | Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Streamsplunk · splunk app for stream · CWE-269 | Критическая9,9 | — | 0,3 % | 1 июн. 2023 г. |
38Наблюдать | CVE-2021-22945Эксплойта нет | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freedhaxx · libcurl · CWE-415 | Критическая9,1 | — | 6,7 % | 23 сент. 2021 г. |
38Наблюдать | CVE-2013-6771Эксплойта нет | Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .splunk · splunk · CWE-22 | Критическая9,3 | — | 4,8 % | 7 авг. 2014 г. |
37Наблюдать | CVE-2022-43568Эксплойта нет | Reflected Cross-Site Scripting via the radio template in Splunk Enterprisesplunk · splunk · CWE-79 | Средняя6,1 | — | 42,8 % | 4 нояб. 2022 г. |
37Наблюдать | CVE-2022-35737Proof of concept | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to asqlite · sqlite · CWE-129 | Высокая7,5 | — | 22,8 % | 3 авг. 2022 г. |
37Наблюдать | CVE-2025-20229Эксплойта нет | Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprisesplunk · splunk · CWE-284 | Высокая8,0 | — | 16,0 % | 26 мар. 2025 г. |
- CVE-2026-2025398Срочно
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %splunk · splunk10 июн. 2026 г.
- CVE-2014-016090Срочно
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %openssl · openssl7 апр. 2014 г.
- CVE-2023-4621462На этой неделе
Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
ВысокаяCVSS 8,8Готовый эксплойтEPSS 89 %splunk · cloud16 нояб. 2023 г.
- CVE-2023-3270759В плане
‘edit_user’ Capability Privilege Escalation
ВысокаяCVSS 8,8Готовый эксплойтEPSS 79 %splunk · splunk1 июн. 2023 г.
- CVE-2018-1140950В плане
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demon
СредняяCVSS 5,3Готовый эксплойтEPSS 98 %splunk · splunk8 июн. 2018 г.
- CVE-2021-2290150В плане
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session t
ВысокаяCVSS 8,1Эксплойта нетEPSS 60 %haxx · curl11 июн. 2021 г.
- CVE-2023-3271445В плане
Path Traversal in Splunk App for Lookup File Editing
ВысокаяCVSS 8,1Эксплойта нетEPSS 43 %splunk · splunk1 июн. 2023 г.
- CVE-2026-2025145В плане
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
ВысокаяCVSS 8,8Proof of conceptEPSS 32 %splunk · splunk10 июн. 2026 г.
- CVE-2022-3220741В плане
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a ren
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %haxx · curl7 июл. 2022 г.
- CVE-2021-3056040В плане
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a
ВысокаяCVSS 8,8Эксплойта нетEPSS 18 %google · chrome3 авг. 2021 г.
- CVE-2022-3222140В плане
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when th
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %haxx · curl5 дек. 2022 г.
- CVE-2016-1012640В плане
Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %splunk · splunk10 янв. 2017 г.
- CVE-2021-352040В плане
There's a flaw in lz4.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %lz4 project · lz42 июн. 2021 г.
- CVE-2017-1706740В плане
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12,
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %splunk · splunk29 нояб. 2017 г.
- CVE-2022-3622740В плане
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %libarchive · libarchive21 нояб. 2022 г.
- CVE-2022-3215840В плане
Splunk Enterprise deployment servers allow client publishing of forwarder bundles
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %splunk · splunk15 июн. 2022 г.
- CVE-2022-4357139Наблюдать
Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
ВысокаяCVSS 8,8Готовый эксплойтEPSS 14 %splunk · splunk3 нояб. 2022 г.
- CVE-2011-464439Наблюдать
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentio
КритическаяCVSS 9,3Proof of conceptEPSS 8 %splunk · splunk3 янв. 2012 г.
- CVE-2022-3743739Наблюдать
Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validation
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %splunk · splunk16 авг. 2022 г.
- CVE-2023-3271339Наблюдать
Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %splunk · splunk app for stream1 июн. 2023 г.
- CVE-2021-2294538Наблюдать
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed
КритическаяCVSS 9,1Эксплойта нетEPSS 7 %haxx · libcurl23 сент. 2021 г.
- CVE-2013-677138Наблюдать
Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %splunk · splunk7 авг. 2014 г.
- CVE-2022-4356837Наблюдать
Reflected Cross-Site Scripting via the radio template in Splunk Enterprise
СредняяCVSS 6,1Эксплойта нетEPSS 43 %splunk · splunk4 нояб. 2022 г.
- CVE-2022-3573737Наблюдать
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a
ВысокаяCVSS 7,5Proof of conceptEPSS 23 %sqlite · sqlite3 авг. 2022 г.
- CVE-2025-2022937Наблюдать
Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprise
ВысокаяCVSS 8,0Эксплойта нетEPSS 16 %splunk · splunk26 мар. 2025 г.