Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2023-32706
On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser with…
Splunk
8.1.14 / 8.2.11+
MEDIUM 6.5
CVE-2023-32716
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulne…
Splunk
8.1.14 / 8.2.11+
MEDIUM 6.1
CVE-2023-32715
In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code into the app, which causes th…
Splunk App For Lookup File Editing
4.0.1+
MEDIUM 5.4
CVE-2023-32711
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, a Splunk dashboard view lets a low-privileged user exploit a vulnerability in the Boot…
Splunk
8.1.14 / 8.2.11+
MEDIUM 5.3
CVE-2023-32710
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can pe…
Splunk
8.1.14 / 8.2.11+
HIGH 8.8
CVE-2023-22935
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass S…
Splunk
8.1.13 / 8.2.10+
HIGH 8.8
CVE-2023-22939
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards…
Splunk
8.1.13 / 8.2.10+
HIGH 8.0
CVE-2023-22934
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguar…
Splunk
8.1.13 / 8.2.10+
HIGH 7.5
CVE-2023-22941
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the …
Splunk
8.1.13 / 8.2.10+
MEDIUM 6.3
CVE-2023-22936
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request for…
Splunk
8.1.13 / 8.2.10+
MEDIUM 6.1
CVE-2023-22932
In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The…
Splunk
9.0.4 / 9.0.2209.3+
MEDIUM 6.1
CVE-2023-22933
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) V…
Splunk
8.1.13 / 8.2.10+
MEDIUM 5.7
CVE-2023-22940
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryi…
Splunk
8.1.13 / 8.2.10+
MEDIUM 5.3
CVE-2023-22943
In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the RE…
Add On Builder
3.1.3 / 4.1.2+
HIGH 8.8
CVE-2022-43565
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker byp…
Splunk
8.1.12 / 8.2.9+
HIGH 8.8
CVE-2022-43567
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the …
Splunk
8.1.12 / 8.2.9+
HIGH 8.0
CVE-2022-43566
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions…
Splunk
8.1.12 / 8.2.9+
MEDIUM 6.5
CVE-2022-43570
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (…
Splunk
8.1.12 / 8.2.9+
MEDIUM 6.5
CVE-2022-43572
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HE…
Splunk
8.1.12 / 8.2.9+
MEDIUM 6.1
CVE-2022-43568EPSS 43%
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON…
Splunk
8.1.12 / 8.2.9+
MEDIUM 5.4
CVE-2022-43569
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persisten…
Splunk
8.1.12 / 8.2.9+
HIGH 8.8
CVE-2022-43563
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards…
Splunk
8.1.12 / 8.2.9+
MEDIUM 6.5
CVE-2022-43564
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a deni…
Splunk
8.1.12 / 8.2.9+
MEDIUM 5.4
CVE-2022-43562
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could le…
Splunk
8.1.12 / 8.2.9+
HIGH 8.8
CVE-2022-43571EPSS 13%
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation c…
Splunk
8.1.12 / 8.2.9+
CRITICAL 9.8
CVE-2022-37437
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is …
Splunk
Mitigation only
MEDIUM 5.5
CVE-2022-37439
In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input c…
Splunk
8.1.11 / 8.2.7.1+
CRITICAL 10.0
CVE-2022-32158
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients t…
Splunk
9.0+
HIGH 8.1
CVE-2022-32154
Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a …
Splunk
8.2.2106 / 9.0+
HIGH 8.1
CVE-2022-32156
In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while con…
Splunk
9.0+