Known vulnerabilities in Splunk Enterprise 9.2.4 - page 2
Vendor:
Splunk Inc.
Software:
Splunk Enterprise
Version:
9.2.4
Software CPE:
cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*
Website:
https://www.splunk.com/
Total vulnerabilities:
133
Public exploits:
4
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
9.4.14
10.0.9
10.2.6
10.4.2
9.3.14
9.4.13
10.0.8
10.2.5
10.4.1
9.3.13
9.4.12
10.2.4
10.0.7
10.4.0
9.3.12
9.4.11
10.0.6
10.2.3
9.3.11
9.4.10
10.0.5
10.2.2
9.3.10
9.4.9
10.0.4
10.2.1
9.2.11
9.4.7
9.2.12
9.3.9
9.4.8
10.0.3
10.2.0
9.2.10
9.3.8
9.4.6
10.0.2
9.4.5
9.3.7
9.2.9
9.2.8
9.3.6
9.4.4
10.0.1
10.0.0
9.4.3
9.3.5
9.2.7
9.1.10
9.4.2
9.3.4
9.2.6
9.1.9
9.4.1
9.3.3
9.2.5
9.1.8
9.4.0
9.3.2
9.2.4
9.1.7
9.3.1
9.2.3
9.1.6
9.0.10
9.1.5
9.2.2
9.3.0
9.2.1
9.1.4
9.0.9
9.2.0
9.1.3
9.0.8
9.1.2
9.0.7
9.1.1
9.0.6
8.2.12
9.1.0
9.0.5
8.2.11
8.1.14
7.1.1
9.0.4
8.2.10
8.1.13
9.0.3
9.0.2
8.2.9
8.1.12
8.2.8
8.2.7.1
8.1.11
9.0.1
9.0.0
8.2.7
8.2.6
8.2.5
8.2.4
8.2.3
8.2.2
8.2.1
8.2.0
8.1.10
8.1.9
8.1.8
8.1.7
8.1.6
8.1.5
8.1.4
8.1.3
8.1.2
8.1.1
8.1.0
8.0.10
8.0.9
8.0.8
8.0.7
8.0.6
8.0.5
8.0.4
8.0.3
8.0.2
8.0.1
8.0.0
7.3.9
7.3.8
7.3.7
7.3.6
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.3.0
7.2.10
7.2.9
7.2.8
7.2.7
7.2.6
7.2.5
7.2.4
7.2.3
7.2.2
7.2.1
7.2.0
7.0.0.1
6.1.14
6.0.15
5.0.19
5.0.0
6.1.0
6.0.0
6.3.0
6.2.14
6.2.0
7.0.1
6.3.12
6.4.9
6.5.6
6.6.4
6.6.3.2
6.3.11
6.4.8
6.4.7
6.5.5
6.5.4
6.5.3
7.0.0
6.6.3
6.6.2
6.6.1
6.6
6.5.2
6.5.1
6.5.0
6.4.6
6.4.5
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.10
6.3.9
6.3.8
6.3.7
6.3.6
6.3.5
6.3.4
6.3.3
6.3.2
6.3.1
6.2.13
6.2.12
6.2.11
6.2.10
6.2.9
6.2.8
6.2.7
6.2.6
6.2.5
6.2.4
6.2.3
6.2.2
6.2.1
6.1.13
6.1.12
6.1.11
6.1.10
6.1.9
6.1.8
6.1.7
6.1.6
6.1.5
6.1.4
6.1.3
6.1.2
6.1.1
6.0.14
6.0.13
6.0.12
6.0.11
6.0.10
6.0.9
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
5.0.18
5.0.17
5.0.16
5.0.15
5.0.14
5.0.13
5.0.12
5.0.11
5.0.10
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
Vulnerabilities (133)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU126412 - Improper Access Control CVE-2026-20203 |
CWE-284 | Low | 9.3.11, 9.4.10, 10.0.5, 10.2.2 | 17.04.2026 |
SB2026041756 |
||
| #VU126411 - Improper Handling of Unicode Encoding CVE-2026-20202 |
CWE-176 | Low | 9.3.11, 9.4.10, 10.0.5, 10.2.2 | 17.04.2026 |
SB2026041756 |
||
| #VU123986 - Information Exposure Through Log Files CVE-2026-20165 |
CWE-532 | Medium | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 13.03.2026 |
SB2026031320 |
||
| #VU123985 - Improper Access Control CVE-2026-20164 |
CWE-284 | Medium | 9.3.10, 9.4.9, 10.0.3, 10.2.0 | 13.03.2026 |
SB2026031320 |
||
| #VU123983 - Command injection CVE-2026-20163 |
CWE-77 | Low | 9.3.10, 9.4.9, 10.0.4, 10.2.0 | 13.03.2026 |
SB2026031318 |
||
| #VU123981 - Resource exhaustion CVE-2025-58181 |
CWE-400 | Medium | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 13.03.2026 |
SB2025122903 SB2026031315 SB2026031321 and 21 more |
||
| #VU121279 - Deserialization of Untrusted Data CVE-2026-21226 |
CWE-502 | Medium | 9.3.10, 9.3.11, 9.4.9, 9.4.10, 10.0.4, 10.0.5, 10.2.1, 10.2.2 | 13.01.2026 |
SB2026011399 SB2026020642 SB2026020977 and 8 more |
||
| #VU120998 - Resource exhaustion CVE-2025-69229 |
CWE-400 | Medium | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 06.01.2026 |
SB2026010643 SB2026012919 SB20260216150 and 10 more |
||
| #VU120997 - Resource Management Errors CVE-2025-69230 |
CWE-399 | Low | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 06.01.2026 |
SB2026010643 SB2026030633 SB2026031147 and 4 more |
||
| #VU120996 - Resource exhaustion CVE-2025-69228 |
CWE-400 | Medium | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 06.01.2026 |
SB2026010643 SB2026012920 SB20260216150 and 9 more |
||
| #VU120995 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2025-69227 |
CWE-835 | Medium | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 06.01.2026 |
SB2026010643 SB2026012920 SB20260216150 and 9 more |
||
| #VU120994 - Exposure of sensitive information to an unauthorized actor CVE-2025-69226 |
CWE-200 | Low | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 06.01.2026 |
SB2026010643 SB20260216150 SB2026030633 and 8 more |
||
| #VU120993 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-69225 |
CWE-444 | Low | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 06.01.2026 |
SB2026010643 SB2026012920 SB20260216150 and 9 more |
||
| #VU120992 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-69224 |
CWE-444 | Low | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 06.01.2026 |
SB2026010643 SB20260216150 SB2026030633 and 8 more |
||
| #VU120990 - Improper Handling of Highly Compressed Data (Data Amplification) CVE-2025-69223 |
CWE-409 | Medium | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 06.01.2026 |
SB2026010643 SB2026012661 SB2026012855 and 15 more |
||
| #VU120612 - Out-of-bounds read CVE-2025-47914 |
CWE-125 | Medium | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 29.12.2025 |
SB2025122903 SB2025122904 SB2025123103 and 19 more |
||
| #VU118717 - Improper input validation CVE-2025-47913 |
CWE-20 | Low | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 24.11.2025 |
SB2025112448 SB2025112455 SB2025112456 and 53 more |
||
| #VU107889 - Improper input validation CVE-2025-22872 |
CWE-20 | Low | 9.3.10, 9.3.12, 9.4.9, 9.4.11, 10.0.4, 10.0.6, 10.2.1, 10.2.3 | 23.04.2025 |
SB2025042357 SB2025042413 SB2025042414 and 51 more |
||
| #VU106253 - Improper input validation CVE-2025-22870 |
CWE-20 | Medium | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 30.03.2025 |
SB2025033001 SB2025033002 SB2025033003 and 106 more |
||
| #VU101894 - Insufficient Technical Documentation CVE-2024-51744 |
CWE-1059 | Low | 9.3.10, 9.4.9, 10.0.4, 10.2.1 | 23.12.2024 |
SB2024122304 SB2024122309 SB20241230139 and 21 more |
Showing elements 21 - 40 out of 133