İçeriğe atla
Noroxi

splunk kayıtları

splunk üreticisine ait 371 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
2 · %0,5
Silahlaştırılmış
8 · %2,2
Pre-auth RCE
7
Düzeltme kaydı olan
%16,2
Yayından KEV’e ortanca
1479 gün

Tüm kayıtlar

371 kayıt
  • Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    splunk · splunk10 Haz 2026

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    openssl · openssl7 Nis 2014

  • CVE-2023-46214
    62Bu hafta

    Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing

    YüksekCVSS 8,8SilahlaştırılmışEPSS %89

    splunk · cloud16 Kas 2023

  • CVE-2023-32707
    59Planlayın

    ‘edit_user’ Capability Privilege Escalation

    YüksekCVSS 8,8SilahlaştırılmışEPSS %79

    splunk · splunk1 Haz 2023

  • CVE-2018-11409
    50Planlayın

    Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demon

    OrtaCVSS 5,3SilahlaştırılmışEPSS %98

    splunk · splunk8 Haz 2018

  • CVE-2021-22901
    50Planlayın

    curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session t

    YüksekCVSS 8,1İstismar yokEPSS %60

    haxx · curl11 Haz 2021

  • CVE-2023-32714
    45Planlayın

    Path Traversal in Splunk App for Lookup File Editing

    YüksekCVSS 8,1İstismar yokEPSS %43

    splunk · splunk1 Haz 2023

  • CVE-2026-20251
    45Planlayın

    Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway

    YüksekCVSS 8,8Kavram kanıtıEPSS %32

    splunk · splunk10 Haz 2026

  • CVE-2022-32207
    41Planlayın

    When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a ren

    KritikCVSS 9,8İstismar yokEPSS %8

    haxx · curl7 Tem 2022

  • CVE-2021-30560
    40Planlayın

    Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a

    YüksekCVSS 8,8İstismar yokEPSS %18

    google · chrome3 Ağu 2021

  • CVE-2022-32221
    40Planlayın

    When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when th

    KritikCVSS 9,8İstismar yokEPSS %4

    haxx · curl5 Ara 2022

  • CVE-2016-10126
    40Planlayın

    Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and

    KritikCVSS 9,8İstismar yokEPSS %4

    splunk · splunk10 Oca 2017

  • CVE-2021-3520
    40Planlayın

    There's a flaw in lz4.

    KritikCVSS 9,8İstismar yokEPSS %3

    lz4 project · lz42 Haz 2021

  • CVE-2017-17067
    40Planlayın

    Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12,

    KritikCVSS 9,8İstismar yokEPSS %3

    splunk · splunk29 Kas 2017

  • CVE-2022-36227
    40Planlayın

    In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th

    KritikCVSS 9,8İstismar yokEPSS %2

    libarchive · libarchive21 Kas 2022

  • CVE-2022-32158
    40Planlayın

    Splunk Enterprise deployment servers allow client publishing of forwarder bundles

    KritikCVSS 10,0İstismar yokEPSS %1

    splunk · splunk15 Haz 2022

  • CVE-2022-43571
    39İzleyin

    Remote Code Execution through dashboard PDF generation component in Splunk Enterprise

    YüksekCVSS 8,8SilahlaştırılmışEPSS %14

    splunk · splunk3 Kas 2022

  • CVE-2011-4644
    39İzleyin

    Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentio

    KritikCVSS 9,3Kavram kanıtıEPSS %8

    splunk · splunk3 Oca 2012

  • CVE-2022-37437
    39İzleyin

    Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validation

    KritikCVSS 9,8İstismar yokEPSS %0

    splunk · splunk16 Ağu 2022

  • CVE-2023-32713
    39İzleyin

    Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream

    KritikCVSS 9,9İstismar yokEPSS %0

    splunk · splunk app for stream1 Haz 2023

  • CVE-2021-22945
    38İzleyin

    When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed

    KritikCVSS 9,1İstismar yokEPSS %7

    haxx · libcurl23 Eyl 2021

  • CVE-2013-6771
    38İzleyin

    Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .

    KritikCVSS 9,3İstismar yokEPSS %5

    splunk · splunk7 Ağu 2014

  • CVE-2022-43568
    37İzleyin

    Reflected Cross-Site Scripting via the radio template in Splunk Enterprise

    OrtaCVSS 6,1İstismar yokEPSS %43

    splunk · splunk4 Kas 2022

  • CVE-2022-35737
    37İzleyin

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a

    YüksekCVSS 7,5Kavram kanıtıEPSS %23

    sqlite · sqlite3 Ağu 2022

  • CVE-2025-20229
    37İzleyin

    Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprise

    YüksekCVSS 8,0İstismar yokEPSS %16

    splunk · splunk26 Mar 2025