Known vulnerabilities in Splunk Enterprise - page 16

Software CPE: cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*
Total vulnerabilities: 472
Public exploits: 25
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Splunk Enterprise Splunk Enterprise is affected by 472 known vulnerabilities: 28 high, 292 medium, 152 low Critical High Medium Low

Vulnerabilities (472)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75792 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-29400
CWE-79 Medium
No
No
8.2.12, 9.0.6, 9.1.1 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 74 more
#VU75791 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-24540
CWE-94 Medium
No
No
8.2.12, 9.0.6, 9.1.1 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 81 more
#VU75790 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-24539
CWE-79 Medium
No
No
8.2.12, 9.0.6, 9.1.1 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 75 more
#VU71577 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-46175
CWE-94 Medium
No
No
8.2.12, 9.0.6, 9.1.1, 9.2.8, 9.3.6, 9.4.4, 10.0.1 26.01.2023 SB2023012644
SB2023012645
SB2023013117
and 44 more
#VU69670 - Improper input validation
CVE-2022-3509
CWE-20 Medium
No
No
8.2.12, 9.0.6, 9.1.1 29.11.2022 SB2022111433
SB2022112934
SB2023011787
and 58 more
#VU69582 - NULL Pointer Dereference
CVE-2022-36227
CWE-476 Low
No
No
8.2.12, 9.0.6, 9.1.1 24.11.2022 SB2022112432
SB2022112437
SB2022112438
and 77 more
#VU68389 - Improper input validation
CVE-2022-2880
CWE-20 Medium
No
No
8.2.12, 9.0.6, 9.1.1 18.10.2022 SB2022101833
SB2022101834
SB2022102005
and 94 more
#VU67414 - Improper Validation of Array Index
CVE-2022-35737
CWE-129 Medium
Available
No
8.2.12, 9.0.6, 9.1.1 15.09.2022 SB2022091537
SB2022092034
SB2022092682
and 72 more
#VU67396 - Improper input validation
CVE-2022-27664
CWE-20 Medium
No
No
8.2.12, 9.0.6, 9.1.1 15.09.2022 SB2022091520
SB2022091521
SB2022092144
and 127 more
#VU66813 - NULL Pointer Dereference
CVE-2022-2309
CWE-476 Medium
No
No
8.2.12, 9.0.6, 9.1.1 29.08.2022 SB2022082928
SB2022082929
SB2022082930
and 28 more
#VU64269 - Integer overflow
CVE-2022-28327
CWE-190 Low
No
No
8.2.12, 9.0.6, 9.1.1 14.06.2022 SB2022041004
SB2022061422
SB2022061506
and 90 more
#VU61394 - UNIX Symbolic Link (Symlink) Following
CVE-2021-31566
CWE-61 Low
No
No
8.2.12, 9.0.6, 9.1.1 15.03.2022 SB2022031530
SB2022031601
SB2022032445
and 27 more
#VU59459 - Use After Free
CVE-2021-36976
CWE-416 Medium
No
No
8.2.12, 9.0.6, 9.1.1 11.01.2022 SB2021072064
SB2022011140
SB2022031433
and 13 more
#VU58271 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41184
CWE-79 Medium
Available
No
8.2.12, 9.0.6, 9.1.1 20.11.2021 SB2021112002
SB2022030804
SB2022041935
and 74 more
#VU58270 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41183
CWE-79 Medium
No
No
8.2.12, 9.0.6, 9.1.1 20.11.2021 SB2021112002
SB2022011943
SB2022011944
and 33 more
#VU53439 - Integer overflow
CVE-2021-3520
CWE-190 High
No
No
8.2.12, 9.0.6, 9.1.1 24.05.2021 SB2021052411
SB2021052522
SB2021052537
and 33 more
#VU52252 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-29425
CWE-22 Low
No
No
8.2.12, 9.0.6, 9.0.9, 9.1.1, 9.1.4, 9.2.1 15.04.2021 SB2021041510
SB2021081922
SB2021093016
and 121 more
#VU29488 - Integer overflow
CVE-2020-14155
CWE-190 High
No
No
8.2.12, 9.0.6, 9.1.1 02.07.2020 SB2020070226
SB2020081713
SB2021010712
and 37 more
#VU29116 - Out-of-bounds read
CVE-2019-20454
CWE-125 Medium
No
No
8.2.12, 9.0.6, 9.1.1 17.06.2020 SB2020021421
SB2020061707
SB2020110528
and 14 more
#VU30256 - Out-of-bounds read
CVE-2019-20838
CWE-125 Medium
No
No
8.2.12, 9.0.6, 9.1.1 15.06.2020 SB2020061529
SB2021010712
SB2021020201
and 24 more


Showing elements 301 - 320 out of 472