splunk

272 tracked vulnerabilities.

CVE-2022-43568 HIGH
Splunk Enterprise <8.1.12-9.0.2 - XSS
Nov 04, 2022
CVSS 8.8
EPSS 0.09
CVE-2022-43567 HIGH
Splunk Enterprise <8.2.9-9.0.2 - Command Injection
Nov 04, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-43566 HIGH
Splunk Enterprise <8.2.9, <8.1.12, <9.0.2 - Privilege Escalation
Nov 04, 2022
CVSS 7.3
EPSS 0.00
CVE-2022-43565 HIGH
Splunk Enterprise <8.2.9, 8.1.12 - CSRF
Nov 04, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-43564 MEDIUM
Splunk Enterprise <8.1.12-9.0.2 - DoS
Nov 04, 2022
CVSS 4.9
EPSS 0.00
CVE-2022-43563 HIGH
Splunk Enterprise <8.2.9, 8.1.12 - Auth Bypass
Nov 04, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-43562 LOW
Splunk Enterprise <8.1.12-9.0.2 - XSS
Nov 04, 2022
CVSS 3.0
EPSS 0.00
CVE-2022-43571 HIGH
Authenticated RCE in Splunk (SimpleXML dashboard PDF generation)
Nov 03, 2022
CVSS 8.8
EPSS 0.76
CVE-2022-43561 MEDIUM
Splunk Enterprise <8.1.12, 8.2.9, 9.0.2 - XSS
Nov 03, 2022
CVSS 6.4
EPSS 0.00
CVE-2022-42915 HIGH
curl 7.77.0-7.85.0 - Double Free via HTTP Proxy CONNECT Error Handling
Oct 29, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-42916 HIGH
curl 7.77.0-7.85.0 - Cleartext Transmission of Sensitive Information via IDN Character Bypass
Oct 29, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-35252 LOW
curl < 7.85.0 - Denial of Service via Cookie Control Code Injection
Sep 23, 2022
CVSS 3.7
EPSS 0.00
CVE-2022-37439 MEDIUM
Splunk Enterprise and Universal Forwarder 8.1.0-8.1.10 - Denial of Service via Malformed ZIP File
Aug 16, 2022
CVSS 5.5
EPSS 0.00
CVE-2022-37438 LOW
Splunk Enterprise 8.1.0-8.1.10 & Splunk Cloud <8.2.2203.4 Authenticated Info Exposure
Aug 16, 2022
CVSS 2.6
EPSS 0.00
CVE-2022-37437 HIGH
Splunk 9.0.0 - Improper Certificate Validation in Ingest Actions S3 Destination
Aug 16, 2022
CVSS 7.4
EPSS 0.00
CVE-2022-35737 HIGH
SQLite 1.0.12-3.39.x - Array Index Overflow via String Argument to C API
Aug 03, 2022
CVSS 7.5
EPSS 0.52
CVE-2022-32208 MEDIUM
curl 7.16.4-7.83.1 - Man-In-The-Middle Attack via FTP KRB5 Message Verification Failure
Jul 07, 2022
CVSS 5.9
EPSS 0.00
CVE-2022-32207 CRITICAL
curl 7.69.0-7.83.1 - Unauthenticated File Permission Overwrite via Atomic Rename
Jul 07, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-32206 MEDIUM
curl < 7.84.0 - Denial of Service via Unbounded HTTP Compression Chain
Jul 07, 2022
CVSS 6.5
EPSS 0.03
CVE-2022-32205 MEDIUM
curl 7.71.0-7.84.0 - Denial of Service via Excessive Set-Cookie Headers
Jul 07, 2022
CVSS 4.3
EPSS 0.02
CVE-2022-32158 CRITICAL
Splunk < 9.0 - Unauthenticated Arbitrary Code Execution via Deployment Server
Jun 15, 2022
CVSS 9.0
EPSS 0.01
CVE-2022-32157 HIGH
Splunk < 9.0 - Unauthenticated Forwarder Bundle Download
Jun 15, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-32156 HIGH
Splunk Enterprise and Universal Forwarder < 9.0 - Improper Certificate Validation in CLI
Jun 15, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-32155 HIGH
Splunk < 9.0 - Unauthenticated Remote Management Services Exposure
Jun 15, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-32154 MEDIUM
Splunk < 9.0 - SPL Safeguard Bypass via Form Token Injection
Jun 15, 2022
CVSS 6.8
EPSS 0.00