Known vulnerabilities in Splunk Enterprise - page 6
Vendor:
Splunk Inc.
Software:
Splunk Enterprise
Software CPE:
cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*
Website:
https://www.splunk.com/
Total vulnerabilities:
472
Public exploits:
25
Known exploited (KEV):
5
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.3.14
9.4.13
10.0.8
10.2.5
10.4.1
9.3.13
9.4.12
10.2.4
10.0.7
10.4.0
9.3.12
9.4.11
10.0.6
10.2.3
9.3.11
9.4.10
10.0.5
10.2.2
9.3.10
9.4.9
10.0.4
10.2.1
9.2.11
9.4.7
9.2.12
9.3.9
9.4.8
10.0.3
10.2.0
9.2.10
9.3.8
9.4.6
10.0.2
9.4.5
9.3.7
9.2.9
9.2.8
9.3.6
9.4.4
10.0.1
10.0.0
9.4.3
9.3.5
9.2.7
9.1.10
9.4.2
9.3.4
9.2.6
9.1.9
9.4.1
9.3.3
9.2.5
9.1.8
9.4.0
9.3.2
9.2.4
9.1.7
9.3.1
9.2.3
9.1.6
9.0.10
9.1.5
9.2.2
9.3.0
9.2.1
9.1.4
9.0.9
9.2.0
9.1.3
9.0.8
9.1.2
9.0.7
9.1.1
9.0.6
8.2.12
9.1.0
9.0.5
8.2.11
8.1.14
7.1.1
9.0.4
8.2.10
8.1.13
9.0.3
9.0.2
8.2.9
8.1.12
8.2.8
8.2.7.1
8.1.11
9.0.1
9.0.0
8.2.7
8.2.6
8.2.5
8.2.4
8.2.3
8.2.2
8.2.1
8.2.0
8.1.10
8.1.9
8.1.8
8.1.7
8.1.6
8.1.5
8.1.4
8.1.3
8.1.2
8.1.1
8.1.0
8.0.10
8.0.9
8.0.8
8.0.7
8.0.6
8.0.5
8.0.4
8.0.3
8.0.2
8.0.1
8.0.0
7.3.9
7.3.8
7.3.7
7.3.6
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.3.0
7.2.10
7.2.9
7.2.8
7.2.7
7.2.6
7.2.5
7.2.4
7.2.3
7.2.2
7.2.1
7.2.0
7.0.0.1
6.1.14
6.0.15
5.0.19
5.0.0
6.1.0
6.0.0
6.3.0
6.2.14
6.2.0
7.0.1
6.3.12
6.4.9
6.5.6
6.6.4
6.6.3.2
6.3.11
6.4.8
6.4.7
6.5.5
6.5.4
6.5.3
7.0.0
6.6.3
6.6.2
6.6.1
6.6
6.5.2
6.5.1
6.5.0
6.4.6
6.4.5
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.10
6.3.9
6.3.8
6.3.7
6.3.6
6.3.5
6.3.4
6.3.3
6.3.2
6.3.1
6.2.13
6.2.12
6.2.11
6.2.10
6.2.9
6.2.8
6.2.7
6.2.6
6.2.5
6.2.4
6.2.3
6.2.2
6.2.1
6.1.13
6.1.12
6.1.11
6.1.10
6.1.9
6.1.8
6.1.7
6.1.6
6.1.5
6.1.4
6.1.3
6.1.2
6.1.1
6.0.14
6.0.13
6.0.12
6.0.11
6.0.10
6.0.9
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
5.0.18
5.0.17
5.0.16
5.0.15
5.0.14
5.0.13
5.0.12
5.0.11
5.0.10
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
Vulnerabilities (472)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU116643 - Improper Access Control CVE-2025-20366 |
CWE-284 | Low | 9.2.8, 9.3.6, 9.4.4 | 07.10.2025 |
SB2025100708 |
||
| #VU116642 - Improper Certificate Validation CVE-2024-1351 |
CWE-295 | Medium | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 07.10.2025 |
SB2024030782 SB2025100707 |
||
| #VU112573 - Exposure of sensitive information to an unauthorized actor CVE-2025-20325 |
CWE-200 | Low | 9.1.10, 9.2.7, 9.3.5, 9.4.3 | 09.07.2025 |
SB2025070910 |
||
| #VU112570 - Improper Access Control CVE-2025-20300 |
CWE-284 | Low | 9.1.9, 9.2.6, 9.3.5, 9.4.2 | 09.07.2025 |
SB2025070908 |
||
| #VU112569 - Improper Access Control CVE-2025-20324 |
CWE-284 | Medium | 9.1.10, 9.2.7, 9.3.5, 9.4.2 | 09.07.2025 |
SB2025070910 |
||
| #VU112567 - Cross-Site Request Forgery (CSRF) CVE-2025-20322 |
CWE-352 | Low | 9.1.10, 9.2.7, 9.3.5, 9.4.3 | 09.07.2025 |
SB2025070910 |
||
| #VU112565 - Cross-Site Request Forgery (CSRF) CVE-2025-20321 |
CWE-352 | Low | 9.1.10, 9.2.7, 9.3.5, 9.4.3 | 09.07.2025 |
SB2025070910 |
||
| #VU112563 - External Control of File Name or Path CVE-2025-20320 |
CWE-73 | Medium | 9.1.10, 9.2.7, 9.3.5, 9.4.3 | 09.07.2025 |
SB2025070910 |
||
| #VU112562 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2025-20319 |
CWE-78 | Low | 9.1.10, 9.2.7, 9.3.5, 9.4.3 | 09.07.2025 |
SB2025070910 |
||
| #VU112106 - Memory corruption CVE-2025-52999 |
CWE-119 | Medium | 9.2.8, 9.2.9, 9.3.6, 9.3.7, 9.4.4, 9.4.5, 10.0.1 | 02.07.2025 |
SB2025070257 SB2025070261 SB2025070262 and 43 more |
||
| #VU111878 - Improper Access Control CVE-2024-7553 |
CWE-284 | Medium | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 24.06.2025 |
SB2025062440 SB2025062503 SB2025100707 |
||
| #VU110073 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-20297 |
CWE-79 | Low | 9.1.9, 9.2.6, 9.3.4, 9.4.2 | 02.06.2025 |
SB2025060246 |
||
| #VU109885 - Improper Certificate Validation CVE-2025-5025 |
CWE-295 | Medium | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 28.05.2025 |
SB2025052805 SB2025060505 SB2025072409 and 4 more |
||
| #VU109884 - Improper Certificate Validation CVE-2025-4947 |
CWE-295 | Low | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 28.05.2025 |
SB2025052805 SB2025060505 SB2025072409 and 4 more |
||
| #VU107596 - Heap-based Buffer Overflow CVE-2025-32415 |
CWE-122 | High | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 17.04.2025 |
SB2025041758 SB2025041880 SB2025042531 and 56 more |
||
| #VU103648 - Exposure of sensitive information to an unauthorized actor CVE-2025-0167 |
CWE-200 | Low | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 05.02.2025 |
SB2025020531 SB2025020601 SB2025020658 and 20 more |
||
| #VU103646 - Integer overflow CVE-2025-0725 |
CWE-190 | High | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 05.02.2025 |
SB2025020531 SB2025020601 SB2025020658 and 25 more |
||
| #VU97574 - Uncontrolled Recursion CVE-2024-7254 |
CWE-674 | Medium | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 19.09.2024 |
SB2024091904 SB2024100103 SB2024101050 and 90 more |
||
| #VU70097 - Heap-based Buffer Overflow CVE-2015-5237 |
CWE-122 | High | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 10.12.2022 |
SB2017092512 SB2023011801 SB2023042744 and 7 more |
||
| #VU64030 - Resource exhaustion CVE-2021-44906 |
CWE-400 | High | 9.2.8, 9.3.6, 9.4.4, 10.0.1 | 07.06.2022 |
SB2022060836 SB2022062103 SB2022062203 and 52 more |
Showing elements 101 - 120 out of 472