Known vulnerabilities in Splunk Enterprise - page 12
Vendor:
Splunk Inc.
Software:
Splunk Enterprise
Software CPE:
cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*
Website:
https://www.splunk.com/
Total vulnerabilities:
472
Public exploits:
25
Known exploited (KEV):
5
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.3.14
9.4.13
10.0.8
10.2.5
10.4.1
9.3.13
9.4.12
10.2.4
10.0.7
10.4.0
9.3.12
9.4.11
10.0.6
10.2.3
9.3.11
9.4.10
10.0.5
10.2.2
9.3.10
9.4.9
10.0.4
10.2.1
9.2.11
9.4.7
9.2.12
9.3.9
9.4.8
10.0.3
10.2.0
9.2.10
9.3.8
9.4.6
10.0.2
9.4.5
9.3.7
9.2.9
9.2.8
9.3.6
9.4.4
10.0.1
10.0.0
9.4.3
9.3.5
9.2.7
9.1.10
9.4.2
9.3.4
9.2.6
9.1.9
9.4.1
9.3.3
9.2.5
9.1.8
9.4.0
9.3.2
9.2.4
9.1.7
9.3.1
9.2.3
9.1.6
9.0.10
9.1.5
9.2.2
9.3.0
9.2.1
9.1.4
9.0.9
9.2.0
9.1.3
9.0.8
9.1.2
9.0.7
9.1.1
9.0.6
8.2.12
9.1.0
9.0.5
8.2.11
8.1.14
7.1.1
9.0.4
8.2.10
8.1.13
9.0.3
9.0.2
8.2.9
8.1.12
8.2.8
8.2.7.1
8.1.11
9.0.1
9.0.0
8.2.7
8.2.6
8.2.5
8.2.4
8.2.3
8.2.2
8.2.1
8.2.0
8.1.10
8.1.9
8.1.8
8.1.7
8.1.6
8.1.5
8.1.4
8.1.3
8.1.2
8.1.1
8.1.0
8.0.10
8.0.9
8.0.8
8.0.7
8.0.6
8.0.5
8.0.4
8.0.3
8.0.2
8.0.1
8.0.0
7.3.9
7.3.8
7.3.7
7.3.6
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.3.0
7.2.10
7.2.9
7.2.8
7.2.7
7.2.6
7.2.5
7.2.4
7.2.3
7.2.2
7.2.1
7.2.0
7.0.0.1
6.1.14
6.0.15
5.0.19
5.0.0
6.1.0
6.0.0
6.3.0
6.2.14
6.2.0
7.0.1
6.3.12
6.4.9
6.5.6
6.6.4
6.6.3.2
6.3.11
6.4.8
6.4.7
6.5.5
6.5.4
6.5.3
7.0.0
6.6.3
6.6.2
6.6.1
6.6
6.5.2
6.5.1
6.5.0
6.4.6
6.4.5
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.10
6.3.9
6.3.8
6.3.7
6.3.6
6.3.5
6.3.4
6.3.3
6.3.2
6.3.1
6.2.13
6.2.12
6.2.11
6.2.10
6.2.9
6.2.8
6.2.7
6.2.6
6.2.5
6.2.4
6.2.3
6.2.2
6.2.1
6.1.13
6.1.12
6.1.11
6.1.10
6.1.9
6.1.8
6.1.7
6.1.6
6.1.5
6.1.4
6.1.3
6.1.2
6.1.1
6.0.14
6.0.13
6.0.12
6.0.11
6.0.10
6.0.9
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
5.0.18
5.0.17
5.0.16
5.0.15
5.0.14
5.0.13
5.0.12
5.0.11
5.0.10
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
Vulnerabilities (472)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU93572 - NULL Pointer Dereference CVE-2024-36982 |
CWE-476 | Medium | 9.0.10, 9.1.5, 9.2.2 | 01.07.2024 |
SB2024070165 |
||
| #VU93571 - Command injection CVE-2024-36983 |
CWE-77 | High | 9.0.10, 9.1.5, 9.2.2 | 01.07.2024 |
SB2024070165 |
||
| #VU93570 - Deserialization of Untrusted Data CVE-2024-36984 |
CWE-502 | Medium | 9.0.10, 9.1.5, 9.2.2 | 01.07.2024 |
SB2024070165 |
||
| #VU93569 - Improper Control of Generation of Code ('Code Injection') CVE-2024-36985 |
CWE-94 | High | 9.0.10, 9.1.5, 9.2.2 | 01.07.2024 |
SB2024070165 |
||
| #VU93568 - Authorization Bypass Through User-Controlled Key CVE-2024-36986 |
CWE-639 | Medium | 9.0.10, 9.1.5, 9.2.2 | 01.07.2024 |
SB2024070165 |
||
| #VU93567 - Unrestricted Upload of File with Dangerous Type CVE-2024-36987 |
CWE-434 | Medium | 9.0.10, 9.1.5, 9.2.2 | 01.07.2024 |
SB2024070165 |
||
| #VU93566 - Improper Access Control CVE-2024-36989 |
CWE-284 | Low | 9.0.10, 9.1.5, 9.2.2 | 01.07.2024 |
SB2024070165 |
||
| #VU93554 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-36990 |
CWE-835 | Medium | 9.0.10, 9.1.5, 9.2.2 | 01.07.2024 |
SB2024070165 |
||
| #VU88828 - Resource exhaustion CVE-2024-3651 |
CWE-400 | Medium | 9.0.9, 9.1.4, 9.1.8, 9.1.9, 9.2.1, 9.2.5, 9.2.6, 9.3.3, 9.3.4, 9.4.1, 9.4.2 | 19.04.2024 |
SB2024041905 SB2024041906 SB2024041907 and 112 more |
||
| #VU84849 - Command injection CVE-2023-5752 |
CWE-77 | Medium | 9.0.9, 9.1.4, 9.2.1 | 28.12.2023 |
SB2023122824 SB2023122825 SB2023122826 and 32 more |
||
| #VU83631 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-47627 |
CWE-444 | Medium | 9.0.9, 9.1.4, 9.2.1 | 04.12.2023 |
SB2023120403 SB2023120406 SB2023120407 and 15 more |
||
| #VU82978 - Exposure of sensitive information to an unauthorized actor CVE-2023-45803 |
CWE-200 | Medium | 9.0.9, 9.1.4, 9.1.6, 9.2.1, 9.2.3, 9.3.1 | 10.11.2023 |
SB2023111038 SB2023111040 SB2023111048 and 122 more |
||
| #VU82226 - Inefficient Regular Expression Complexity CVE-2022-40896 |
CWE-1333 | Medium | 9.0.9, 9.1.4, 9.2.1 | 18.10.2023 |
SB20231018123 SB2023121111 SB2023122110 and 15 more |
||
| #VU82122 - Improper input validation CVE-2023-35116 |
CWE-20 | Low | 9.0.9, 9.1.4, 9.2.1 | 17.10.2023 |
SB2023101771 SB20231018117 SB2023101925 and 45 more |
||
| #VU81322 - Exposure of sensitive information to an unauthorized actor CVE-2023-43804 |
CWE-200 | Low | 9.0.9, 9.1.4, 9.1.6, 9.2.1, 9.2.3, 9.3.1 | 02.10.2023 |
SB2023100251 SB2023100259 SB2023100260 and 112 more |
||
| #VU78448 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-37276 |
CWE-444 | Medium | 9.0.9, 9.1.4, 9.2.1 | 20.07.2023 |
SB2023072024 SB2024013032 SB2024021609 and 3 more |
||
| #VU77651 - Improper Control of Generation of Code ('Code Injection') CVE-2023-33733 |
CWE-94 | High | 9.0.10, 9.1.5, 9.2.2 | 22.06.2023 |
SB2023062280 SB2023062282 SB2023062845 and 6 more |
||
| #VU77164 - Exposure of sensitive information to an unauthorized actor CVE-2023-32681 |
CWE-200 | Medium | 9.0.9, 9.1.4, 9.2.1 | 12.06.2023 |
SB2023061224 SB2023061306 SB2023061514 and 113 more |
||
| #VU77107 - Incorrect Default Permissions CVE-2023-2976 |
CWE-276 | Low | 9.0.9, 9.1.4, 9.2.1 | 08.06.2023 |
SB2023060849 SB2023071712 SB2023072512 and 157 more |
||
| #VU71377 - Improper input validation CVE-2022-40898 |
CWE-20 | Medium | 9.0.9, 9.1.4, 9.2.1 | 20.01.2023 |
SB2023012007 SB2023012013 SB2023012014 and 22 more |
Showing elements 221 - 240 out of 472