splunk kayıtları
splunk üreticisine ait 371 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %0,5
- Silahlaştırılmış
- 8 · %2,2
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %16,2
- Yayından KEV’e ortanca
- 1479 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')53
- CWE-20 Improper Input Validation31
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor29
- CWE-284 Improper Access Control17
- CWE-862 Missing Authorization14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')13
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
371 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2026-20253Silahlaştırılmış | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprisesplunk · splunk · CWE-306 | Kritik9,8 | KEV | %96,9 | 10 Haz 2026 |
90Hemen | CVE-2014-0160Silahlaştırılmış | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Yüksek7,5 | KEV | %100,0 | 7 Nis 2014 |
62Bu hafta | CVE-2023-46214Silahlaştırılmış | Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsingsplunk · cloud · CWE-91 | Yüksek8,8 | — | %89,2 | 16 Kas 2023 |
59Planlayın | CVE-2023-32707Silahlaştırılmış | ‘edit_user’ Capability Privilege Escalationsplunk · splunk · CWE-285 | Yüksek8,8 | — | %79,0 | 1 Haz 2023 |
50Planlayın | CVE-2018-11409Silahlaştırılmış | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonsplunk · splunk · CWE-200 | Orta5,3 | — | %98,3 | 8 Haz 2018 |
50Planlayın | CVE-2021-22901İstismar yok | curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session thaxx · curl · CWE-416 | Yüksek8,1 | — | %60,1 | 11 Haz 2021 |
45Planlayın | CVE-2023-32714İstismar yok | Path Traversal in Splunk App for Lookup File Editingsplunk · splunk · CWE-35 | Yüksek8,1 | — | %42,8 | 1 Haz 2023 |
45Planlayın | CVE-2026-20251Kavram kanıtı | Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gatewaysplunk · splunk · CWE-502 | Yüksek8,8 | — | %32,2 | 10 Haz 2026 |
41Planlayın | CVE-2022-32207İstismar yok | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a renhaxx · curl · CWE-840 | Kritik9,8 | — | %7,7 | 7 Tem 2022 |
40Planlayın | CVE-2021-30560İstismar yok | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a google · chrome · CWE-416 | Yüksek8,8 | — | %17,6 | 3 Ağu 2021 |
40Planlayın | CVE-2022-32221İstismar yok | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when thhaxx · curl · CWE-200 | Kritik9,8 | — | %4,4 | 5 Ara 2022 |
40Planlayın | CVE-2016-10126İstismar yok | Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and splunk · splunk · CWE-264 | Kritik9,8 | — | %4,0 | 10 Oca 2017 |
40Planlayın | CVE-2021-3520İstismar yok | There's a flaw in lz4.lz4 project · lz4 · CWE-190 | Kritik9,8 | — | %3,2 | 2 Haz 2021 |
40Planlayın | CVE-2017-17067İstismar yok | Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12,splunk · splunk · CWE-863 | Kritik9,8 | — | %3,0 | 29 Kas 2017 |
40Planlayın | CVE-2022-36227İstismar yok | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if thlibarchive · libarchive · CWE-476 | Kritik9,8 | — | %2,4 | 21 Kas 2022 |
40Planlayın | CVE-2022-32158İstismar yok | Splunk Enterprise deployment servers allow client publishing of forwarder bundlessplunk · splunk · CWE-284 | Kritik10,0 | — | %1,4 | 15 Haz 2022 |
39İzleyin | CVE-2022-43571Silahlaştırılmış | Remote Code Execution through dashboard PDF generation component in Splunk Enterprisesplunk · splunk · CWE-94 | Yüksek8,8 | — | %13,8 | 3 Kas 2022 |
39İzleyin | CVE-2011-4644Kavram kanıtı | Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentiosplunk · splunk · CWE-287 | Kritik9,3 | — | %7,5 | 3 Oca 2012 |
39İzleyin | CVE-2022-37437İstismar yok | Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validationsplunk · splunk · CWE-295 | Kritik9,8 | — | %0,4 | 16 Ağu 2022 |
39İzleyin | CVE-2023-32713İstismar yok | Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Streamsplunk · splunk app for stream · CWE-269 | Kritik9,9 | — | %0,3 | 1 Haz 2023 |
38İzleyin | CVE-2021-22945İstismar yok | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freedhaxx · libcurl · CWE-415 | Kritik9,1 | — | %6,7 | 23 Eyl 2021 |
38İzleyin | CVE-2013-6771İstismar yok | Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .splunk · splunk · CWE-22 | Kritik9,3 | — | %4,8 | 7 Ağu 2014 |
37İzleyin | CVE-2022-43568İstismar yok | Reflected Cross-Site Scripting via the radio template in Splunk Enterprisesplunk · splunk · CWE-79 | Orta6,1 | — | %42,8 | 4 Kas 2022 |
37İzleyin | CVE-2022-35737Kavram kanıtı | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to asqlite · sqlite · CWE-129 | Yüksek7,5 | — | %22,8 | 3 Ağu 2022 |
37İzleyin | CVE-2025-20229İstismar yok | Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprisesplunk · splunk · CWE-284 | Yüksek8,0 | — | %16,0 | 26 Mar 2025 |
- CVE-2026-2025398Hemen
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97splunk · splunk10 Haz 2026
- CVE-2014-016090Hemen
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100openssl · openssl7 Nis 2014
- CVE-2023-4621462Bu hafta
Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
YüksekCVSS 8,8SilahlaştırılmışEPSS %89splunk · cloud16 Kas 2023
- CVE-2023-3270759Planlayın
‘edit_user’ Capability Privilege Escalation
YüksekCVSS 8,8SilahlaştırılmışEPSS %79splunk · splunk1 Haz 2023
- CVE-2018-1140950Planlayın
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demon
OrtaCVSS 5,3SilahlaştırılmışEPSS %98splunk · splunk8 Haz 2018
- CVE-2021-2290150Planlayın
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session t
YüksekCVSS 8,1İstismar yokEPSS %60haxx · curl11 Haz 2021
- CVE-2023-3271445Planlayın
Path Traversal in Splunk App for Lookup File Editing
YüksekCVSS 8,1İstismar yokEPSS %43splunk · splunk1 Haz 2023
- CVE-2026-2025145Planlayın
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
YüksekCVSS 8,8Kavram kanıtıEPSS %32splunk · splunk10 Haz 2026
- CVE-2022-3220741Planlayın
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a ren
KritikCVSS 9,8İstismar yokEPSS %8haxx · curl7 Tem 2022
- CVE-2021-3056040Planlayın
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a
YüksekCVSS 8,8İstismar yokEPSS %18google · chrome3 Ağu 2021
- CVE-2022-3222140Planlayın
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when th
KritikCVSS 9,8İstismar yokEPSS %4haxx · curl5 Ara 2022
- CVE-2016-1012640Planlayın
Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and
KritikCVSS 9,8İstismar yokEPSS %4splunk · splunk10 Oca 2017
- CVE-2021-352040Planlayın
There's a flaw in lz4.
KritikCVSS 9,8İstismar yokEPSS %3lz4 project · lz42 Haz 2021
- CVE-2017-1706740Planlayın
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12,
KritikCVSS 9,8İstismar yokEPSS %3splunk · splunk29 Kas 2017
- CVE-2022-3622740Planlayın
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th
KritikCVSS 9,8İstismar yokEPSS %2libarchive · libarchive21 Kas 2022
- CVE-2022-3215840Planlayın
Splunk Enterprise deployment servers allow client publishing of forwarder bundles
KritikCVSS 10,0İstismar yokEPSS %1splunk · splunk15 Haz 2022
- CVE-2022-4357139İzleyin
Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
YüksekCVSS 8,8SilahlaştırılmışEPSS %14splunk · splunk3 Kas 2022
- CVE-2011-464439İzleyin
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentio
KritikCVSS 9,3Kavram kanıtıEPSS %8splunk · splunk3 Oca 2012
- CVE-2022-3743739İzleyin
Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validation
KritikCVSS 9,8İstismar yokEPSS %0splunk · splunk16 Ağu 2022
- CVE-2023-3271339İzleyin
Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream
KritikCVSS 9,9İstismar yokEPSS %0splunk · splunk app for stream1 Haz 2023
- CVE-2021-2294538İzleyin
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed
KritikCVSS 9,1İstismar yokEPSS %7haxx · libcurl23 Eyl 2021
- CVE-2013-677138İzleyin
Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .
KritikCVSS 9,3İstismar yokEPSS %5splunk · splunk7 Ağu 2014
- CVE-2022-4356837İzleyin
Reflected Cross-Site Scripting via the radio template in Splunk Enterprise
OrtaCVSS 6,1İstismar yokEPSS %43splunk · splunk4 Kas 2022
- CVE-2022-3573737İzleyin
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a
YüksekCVSS 7,5Kavram kanıtıEPSS %23sqlite · sqlite3 Ağu 2022
- CVE-2025-2022937İzleyin
Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprise
YüksekCVSS 8,0İstismar yokEPSS %16splunk · splunk26 Mar 2025