Known vulnerabilities in Splunk Enterprise 9.1.3 - page 4

Version: 9.1.3
Software CPE: cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*
Total vulnerabilities: 226
Public exploits: 13
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Splunk Enterprise version 9.1.3 Splunk Enterprise 9.1.3 is affected by 226 vulnerabilities: 11 high, 136 medium, 79 low Critical High Medium Low

Vulnerabilities (226)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU120254 - Improper Handling of Length Parameter Inconsistency
CVE-2025-14847
CWE-130 High
Public exploit available
Exploited
9.2.12, 9.3.9, 9.4.8, 10.0.3, 10.2.0 23.12.2025 SB2025122318
SB2026011607
SB2026012973
and 9 more
#VU119140 - Improper Access Control
CVE-2025-20383
CWE-284 Low
No
No
9.2.10, 9.3.8, 9.4.6, 10.0.2 04.12.2025 SB2025120435
#VU119139 - Improper input validation
CVE-2025-20389
CWE-20 Low
No
No
9.2.10, 9.3.8, 9.4.6, 10.0.2 04.12.2025 SB2025120435
#VU119120 - Server-Side Request Forgery (SSRF)
CVE-2025-20388
CWE-918 Low
No
No
9.2.10, 9.3.8, 9.4.6, 10.0.2 04.12.2025 SB2025120404
#VU119119 - Incorrect Permission Assignment for Critical Resource
CVE-2025-20386
CWE-732 Low
No
No
9.2.10, 9.3.8, 9.4.6, 10.0.2 04.12.2025 SB2025120404
#VU119118 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-20385
CWE-79 Low
No
No
9.2.10, 9.3.8, 9.4.6, 10.0.2 04.12.2025 SB2025120404
#VU118190 - Resource exhaustion
CVE-2025-58183
CWE-400 Medium
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.11.2025 SB2025110705
SB2025110725
SB2025110726
and 177 more
#VU118189 - Improper input validation
CVE-2025-58188
CWE-20 Medium
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 110 more
#VU118188 - Allocation of Resources Without Limits or Throttling
CVE-2025-58186
CWE-770 Medium
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.11.2025 SB2025110705
SB2025110731
SB2025120304
and 19 more
#VU118187 - Resource exhaustion
CVE-2025-58185
CWE-400 Medium
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 112 more
#VU118186 - Improper input validation
CVE-2025-47912
CWE-20 Low
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.11.2025 SB2025110705
SB2025110731
SB2025120304
and 21 more
#VU118183 - Improper Encoding or Escaping of Output
CVE-2025-58189
CWE-116 Low
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.11.2025 SB2025110705
SB2025110711
SB2025110712
and 120 more
#VU116213 - Out-of-bounds write
CVE-2025-9230
CWE-787 Medium
No
No
9.2.12, 9.3.9, 9.4.8, 10.0.3 01.10.2025 SB2025100119
SB2025100132
SB2025100133
and 108 more
#VU114080 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-47907
CWE-362 Low
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 50 more
#VU114079 - Improper input validation
CVE-2025-47906
CWE-20 Low
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 130 more
#VU113069 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-53643
CWE-444 Medium
No
No
9.2.12, 9.3.9, 9.4.8, 10.0.3 18.07.2025 SB2025071857
SB2025090377
SB2025091303
and 15 more
#VU110253 - Protection Mechanism Failure
CVE-2025-22874
CWE-693 Low
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.06.2025 SB2025060702
SB2025061002
SB2025081114
and 16 more
#VU110252 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-0913
CWE-59 Low
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.06.2025 SB2025060702
SB2025061002
SB2025061003
and 8 more
#VU110251 - Exposure of sensitive information to an unauthorized actor
CVE-2025-4673
CWE-200 Low
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 07.06.2025 SB2025060701
SB2025060702
SB2025061002
and 35 more
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more


Showing elements 61 - 80 out of 226