Known vulnerabilities in Splunk Enterprise 9.1.3 - page 6
Vendor:
Splunk Inc.
Software:
Splunk Enterprise
Version:
9.1.3
Software CPE:
cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*
Website:
https://www.splunk.com/
Total vulnerabilities:
226
Public exploits:
13
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
9.4.14
10.0.9
10.2.6
10.4.2
9.3.14
9.4.13
10.0.8
10.2.5
10.4.1
9.3.13
9.4.12
10.2.4
10.0.7
10.4.0
9.3.12
9.4.11
10.0.6
10.2.3
9.3.11
9.4.10
10.0.5
10.2.2
9.3.10
9.4.9
10.0.4
10.2.1
9.2.11
9.4.7
9.2.12
9.3.9
9.4.8
10.0.3
10.2.0
9.2.10
9.3.8
9.4.6
10.0.2
9.4.5
9.3.7
9.2.9
9.2.8
9.3.6
9.4.4
10.0.1
10.0.0
9.4.3
9.3.5
9.2.7
9.1.10
9.4.2
9.3.4
9.2.6
9.1.9
9.4.1
9.3.3
9.2.5
9.1.8
9.4.0
9.3.2
9.2.4
9.1.7
9.3.1
9.2.3
9.1.6
9.0.10
9.1.5
9.2.2
9.3.0
9.2.1
9.1.4
9.0.9
9.2.0
9.1.3
9.0.8
9.1.2
9.0.7
9.1.1
9.0.6
8.2.12
9.1.0
9.0.5
8.2.11
8.1.14
7.1.1
9.0.4
8.2.10
8.1.13
9.0.3
9.0.2
8.2.9
8.1.12
8.2.8
8.2.7.1
8.1.11
9.0.1
9.0.0
8.2.7
8.2.6
8.2.5
8.2.4
8.2.3
8.2.2
8.2.1
8.2.0
8.1.10
8.1.9
8.1.8
8.1.7
8.1.6
8.1.5
8.1.4
8.1.3
8.1.2
8.1.1
8.1.0
8.0.10
8.0.9
8.0.8
8.0.7
8.0.6
8.0.5
8.0.4
8.0.3
8.0.2
8.0.1
8.0.0
7.3.9
7.3.8
7.3.7
7.3.6
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.3.0
7.2.10
7.2.9
7.2.8
7.2.7
7.2.6
7.2.5
7.2.4
7.2.3
7.2.2
7.2.1
7.2.0
7.0.0.1
6.1.14
6.0.15
5.0.19
5.0.0
6.1.0
6.0.0
6.3.0
6.2.14
6.2.0
7.0.1
6.3.12
6.4.9
6.5.6
6.6.4
6.6.3.2
6.3.11
6.4.8
6.4.7
6.5.5
6.5.4
6.5.3
7.0.0
6.6.3
6.6.2
6.6.1
6.6
6.5.2
6.5.1
6.5.0
6.4.6
6.4.5
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.10
6.3.9
6.3.8
6.3.7
6.3.6
6.3.5
6.3.4
6.3.3
6.3.2
6.3.1
6.2.13
6.2.12
6.2.11
6.2.10
6.2.9
6.2.8
6.2.7
6.2.6
6.2.5
6.2.4
6.2.3
6.2.2
6.2.1
6.1.13
6.1.12
6.1.11
6.1.10
6.1.9
6.1.8
6.1.7
6.1.6
6.1.5
6.1.4
6.1.3
6.1.2
6.1.1
6.0.14
6.0.13
6.0.12
6.0.11
6.0.10
6.0.9
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
5.0.18
5.0.17
5.0.16
5.0.15
5.0.14
5.0.13
5.0.12
5.0.11
5.0.10
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
Vulnerabilities (226)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU106069 - Improper Access Control CVE-2025-20230 |
CWE-284 | Medium | 9.1.8, 9.2.5, 9.3.3, 9.4.1 | 26.03.2025 |
SB2025032671 |
||
| #VU106068 - Information Exposure Through Log Files CVE-2025-20231 |
CWE-532 | Medium | 9.1.8, 9.2.5, 9.3.3, 9.4.1 | 26.03.2025 |
SB2025032670 |
||
| #VU106067 - Improper input validation CVE-2025-20227 |
CWE-20 | Low | 9.1.8, 9.2.5, 9.3.3, 9.4.1 | 26.03.2025 |
SB2025032668 |
||
| #VU106066 - Exposure of sensitive information to an unauthorized actor CVE-2025-20226 |
CWE-200 | Medium | 9.1.8, 9.2.5, 9.3.3, 9.4.1 | 26.03.2025 |
SB2025032668 |
||
| #VU106065 - Exposure of sensitive information to an unauthorized actor CVE-2025-20232 |
CWE-200 | Medium | 9.1.8, 9.2.5, 9.3.3 | 26.03.2025 |
SB2025032668 |
||
| #VU106064 - Cross-Site Request Forgery (CSRF) CVE-2025-20228 |
CWE-352 | Medium | 9.1.8, 9.2.5, 9.3.3 | 26.03.2025 |
SB2025032668 |
||
| #VU106063 - Unrestricted Upload of File with Dangerous Type CVE-2025-20229 |
CWE-434 | Medium | 9.1.8, 9.2.5, 9.3.3 | 26.03.2025 |
SB2025032668 |
||
| #VU105459 - Resource exhaustion CVE-2025-22869 |
CWE-400 | Low | 9.1.9, 9.2.6, 9.3.4, 9.4.2 | 10.03.2025 |
SB2025031011 SB2025031015 SB2025032557 and 108 more |
||
| #VU101663 - Improper Access Control CVE-2024-53243 |
CWE-284 | Low | 9.1.7, 9.2.4, 9.3.2 | 11.12.2024 |
SB2024121149 SB2024121150 |
||
| #VU101662 - Exposure of sensitive information to an unauthorized actor CVE-2024-53244 |
CWE-200 | Low | 9.1.7, 9.2.4, 9.3.2 | 11.12.2024 |
SB2024121147 SB2024121148 |
||
| #VU101661 - Exposure of sensitive information to an unauthorized actor CVE-2024-53245 |
CWE-200 | Low | 9.1.7, 9.2.4 | 11.12.2024 |
SB2024121145 SB2024121146 |
||
| #VU101660 - Exposure of sensitive information to an unauthorized actor CVE-2024-53246 |
CWE-200 | Low | 9.1.7, 9.2.4, 9.3.2 | 11.12.2024 |
SB2024121143 SB2024121144 |
||
| #VU101655 - Deserialization of Untrusted Data CVE-2024-53247 |
CWE-502 | Medium | 9.1.7, 9.2.4, 9.3.2 | 11.12.2024 |
SB2024121140 SB2024121141 |
||
| #VU99350 - Missing release of memory after effective lifetime CVE-2024-36114 |
CWE-401 | Medium | 9.1.7, 9.2.4, 9.3.2 | 25.10.2024 |
SB2024102535 SB2024121139 SB2025012230 and 5 more |
||
| #VU97217 - Resource exhaustion CVE-2024-34158 |
CWE-400 | Medium | 9.1.9, 9.2.6, 9.3.4, 9.4.2 | 12.09.2024 |
SB2024091261 SB2024091264 SB2024091265 and 76 more |
||
| #VU97215 - Resource exhaustion CVE-2024-34155 |
CWE-400 | Medium | 9.1.9, 9.2.6, 9.3.4, 9.4.2 | 12.09.2024 |
SB2024091261 SB2024091264 SB2024091265 and 81 more |
||
| #VU95571 - Command injection CVE-2024-6923 |
CWE-77 | Medium | 9.1.8, 9.2.5, 9.3.3, 9.4.1 | 08.08.2024 |
SB2024080861 SB2024080862 SB2024080863 and 144 more |
||
| #VU93850 - Resource exhaustion CVE-2024-24791 |
CWE-400 | Medium | 9.1.9, 9.2.6, 9.3.4, 9.4.2 | 07.07.2024 |
SB2024070727 SB2024070728 SB2024070729 and 86 more |
||
| #VU93424 - Out-of-bounds read CVE-2024-5535 |
CWE-125 | Low | 9.1.7, 9.2.4, 9.3.2 | 27.06.2024 |
SB2024062720 SB20240717135 SB2024072154 and 157 more |
||
| #VU91596 - Memory corruption CVE-2024-36129 |
CWE-119 | High | 9.1.7, 9.2.4, 9.3.2 | 10.06.2024 |
SB2024061020 SB2024061021 SB2024061741 and 2 more |
Showing elements 101 - 120 out of 226