Known vulnerabilities in Splunk Enterprise 9.2.4 - page 2

Version: 9.2.4
Software CPE: cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*
Total vulnerabilities: 133
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Splunk Enterprise version 9.2.4 Splunk Enterprise 9.2.4 is affected by 133 vulnerabilities: 10 high, 71 medium, 52 low Critical High Medium Low

Vulnerabilities (133)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126412 - Improper Access Control
CVE-2026-20203
CWE-284 Low
No
No
9.3.11, 9.4.10, 10.0.5, 10.2.2 17.04.2026 SB2026041756
#VU126411 - Improper Handling of Unicode Encoding
CVE-2026-20202
CWE-176 Low
No
No
9.3.11, 9.4.10, 10.0.5, 10.2.2 17.04.2026 SB2026041756
#VU123986 - Information Exposure Through Log Files
CVE-2026-20165
CWE-532 Medium
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 13.03.2026 SB2026031320
#VU123985 - Improper Access Control
CVE-2026-20164
CWE-284 Medium
No
No
9.3.10, 9.4.9, 10.0.3, 10.2.0 13.03.2026 SB2026031320
#VU123983 - Command injection
CVE-2026-20163
CWE-77 Low
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.0 13.03.2026 SB2026031318
#VU123981 - Resource exhaustion
CVE-2025-58181
CWE-400 Medium
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 13.03.2026 SB2025122903
SB2026031315
SB2026031321
and 21 more
#VU121279 - Deserialization of Untrusted Data
CVE-2026-21226
CWE-502 Medium
No
No
9.3.10, 9.3.11, 9.4.9, 9.4.10, 10.0.4, 10.0.5, 10.2.1, 10.2.2 13.01.2026 SB2026011399
SB2026020642
SB2026020977
and 8 more
#VU120998 - Resource exhaustion
CVE-2025-69229
CWE-400 Medium
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 06.01.2026 SB2026010643
SB2026012919
SB20260216150
and 10 more
#VU120997 - Resource Management Errors
CVE-2025-69230
CWE-399 Low
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 06.01.2026 SB2026010643
SB2026030633
SB2026031147
and 4 more
#VU120996 - Resource exhaustion
CVE-2025-69228
CWE-400 Medium
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120995 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2025-69227
CWE-835 Medium
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120994 - Exposure of sensitive information to an unauthorized actor
CVE-2025-69226
CWE-200 Low
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 06.01.2026 SB2026010643
SB20260216150
SB2026030633
and 8 more
#VU120993 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-69225
CWE-444 Low
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120992 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-69224
CWE-444 Low
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 06.01.2026 SB2026010643
SB20260216150
SB2026030633
and 8 more
#VU120990 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2025-69223
CWE-409 Medium
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 06.01.2026 SB2026010643
SB2026012661
SB2026012855
and 15 more
#VU120612 - Out-of-bounds read
CVE-2025-47914
CWE-125 Medium
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 29.12.2025 SB2025122903
SB2025122904
SB2025123103
and 19 more
#VU118717 - Improper input validation
CVE-2025-47913
CWE-20 Low
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 24.11.2025 SB2025112448
SB2025112455
SB2025112456
and 53 more
#VU107889 - Improper input validation
CVE-2025-22872
CWE-20 Low
No
No
9.3.10, 9.3.12, 9.4.9, 9.4.11, 10.0.4, 10.0.6, 10.2.1, 10.2.3 23.04.2025 SB2025042357
SB2025042413
SB2025042414
and 51 more
#VU106253 - Improper input validation
CVE-2025-22870
CWE-20 Medium
Public exploit available
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 30.03.2025 SB2025033001
SB2025033002
SB2025033003
and 106 more
#VU101894 - Insufficient Technical Documentation
CVE-2024-51744
CWE-1059 Low
No
No
9.3.10, 9.4.9, 10.0.4, 10.2.1 23.12.2024 SB2024122304
SB2024122309
SB20241230139
and 21 more


Showing elements 21 - 40 out of 133