Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-36996 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine wheth… Splunk 9.1.5 / 9.1.2312.109+ Fix from $1,6002024-07-01 HIGH 7.5 CVE-2024-36991EPSS 13% In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoi… Splunk 9.0.10 / 9.1.5+ Fix from $1,9502024-07-01 MEDIUM 6.5 CVE-2024-36987 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged … Cloud 9.0.10 / 9.1.5+ Fix from $1,6002024-07-01 MEDIUM 6.5 CVE-2024-36990 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged … Splunk 9.0.10 / 9.1.5+ Fix from $1,6002024-07-01 HIGH 8.8 CVE-2024-36983 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated… Splunk 9.0.10 / 9.1.5+ Fix from $1,9502024-07-01 HIGH 8.8 CVE-2024-36984 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they coul… Splunk 9.0.10 / 9.1.5+ Fix from $1,9502024-07-01 HIGH 8.8 CVE-2024-36985EPSS 6% In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a … Splunk 9.0.10 / 9.1.5+ Fix from $1,9502024-07-01 HIGH 7.5 CVE-2024-36982 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker coul… Cloud 9.0.10 / 9.1.5+ Fix from $1,9502024-07-01 MEDIUM 5.7 CVE-2024-36986 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated… Cloud 9.0.10 / 9.1.5+ Fix from $1,6002024-07-01 HIGH 8.1 CVE-2024-29946 In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let atta… Splunk 9.0.9 / 9.1.4+ Fix from $1,9502024-03-27 HIGH 7.2 CVE-2024-29945 In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation proce… Splunk 9.0.9 / 9.1.4+ Fix from $1,9502024-03-27 HIGH 7.2 CVE-2023-46231 In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on … Add On Builder 4.1.4+ Fix from $1,9502024-01-30 HIGH 8.8 CVE-2024-23678 In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the u… Splunk 9.0.8 / 9.1.3+ Fix from $1,9502024-01-22 MEDIUM 6.5 CVE-2024-23675 In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST… Cloud 9.0.8 / 9.1.3+ Fix from $1,6002024-01-22 MEDIUM 5.3 CVE-2024-23677 In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file. Cloud 9.0.8 / 9.0.2208+ Fix from $1,6002024-01-22 MEDIUM 6.5 CVE-2024-22165 In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). … Enterprise Security 7.1.2+ Fix from $1,6002024-01-09 HIGH 8.8 CVE-2023-46214EPSS 89% In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT)… Cloud 9.0.7 / 9.1.2+ Fix from $1,9502023-11-16 HIGH 8.6 CVE-2023-4571 In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Ins… It Service Intelligence 4.13.3 / 4.15.3+ Fix from $1,9502023-08-30 HIGH 8.8 CVE-2023-40595 In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serial… Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 HIGH 8.8 CVE-2023-40596 In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an ins… Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 HIGH 8.8 CVE-2023-40597 In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that … Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 HIGH 8.8 CVE-2023-40598 In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The at… Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 HIGH 7.5 CVE-2023-40593 In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request t… Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 HIGH 7.5 CVE-2023-40594 In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS)… Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 MEDIUM 6.1 CVE-2023-40592 In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scr… Splunk 8.2.12 / 9.0.6+ Fix from $1,6002023-08-30 HIGH 7.8 CVE-2023-3997 Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can se… Soar 6.1.0 / 6.1.0.131+ Fix from $1,9502023-07-31 CRITICAL 9.9 CVE-2023-32713 In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Str… Splunk App For Stream 8.1.1+ Fix from $2,3002023-06-01 HIGH 8.8 CVE-2023-32707EPSS 79% In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who hol… Splunk 8.1.14 / 8.2.11+ Fix from $1,9502023-06-01 HIGH 8.8 CVE-2023-32708 In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigg… Splunk 8.1.14 / 8.2.11+ Fix from $1,9502023-06-01 HIGH 8.1 CVE-2023-32714EPSS 43% In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path trave… Splunk 4.0.1 / 8.1.14+ Fix from $1,9502023-06-01