← Back

Splunk

splunk

276 CVEs • 16 products

Products (16)

Click to collapse
Toggle

CVEs (276)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Debian
HaxxOracle+2 more
5Communications Cloud Native Core Policy
Debian LinuxLibcurl+2 more
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
5Debian
FujitsuHaxx+2 more
10Curl
Debian LinuxM10 1 Firmware+7 more
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
4Debian
HaxxSiemens+1 more
5Curl
Debian LinuxSimatic Tim 1531 Irc Firmware+2 more
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
6Apple
GitlabNetapp+3 more
15Active Iq Unified Manager
Cloud BackupClustered Data Ontap+12 more
Jun 17, 2026
Jun 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
3Apple
PcreSplunk
3Macos
PcreUniversal Forwarder
Jun 17, 2026
Jun 15, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
3Fedoraproject
PcreSplunk
3Fedora
Pcre2Universal Forwarder
Jun 17, 2026
Feb 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulne...Show more
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.c.Show less
1Splunk
1Splunk
Nov 21, 2024
Jan 23, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges
1Splunk
1Splunk
Nov 21, 2024
Jan 23, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking
27Anynines
ApigeeAppdynamics+24 more
55Application Analytics
Application MonitoringApplication Performance Monitoring+52 more
Jun 17, 2026
Aug 5, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.Show less
1Splunk
1Software Development Kit
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.
1Splunk
1Splunk
Jun 17, 2026
Feb 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138...Show more
Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138827.Show less
1Splunk
1Splunk
Jun 17, 2026
Oct 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote attackers to cause a denial of service via a crafted HTTP request.
1Splunk
1Splunk
Jun 17, 2026
Oct 23, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3; and Splunk L...Show more
Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.Show less
1Splunk
1Splunk
Jun 17, 2026
Oct 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to cause a denial of service via a malformed HTTP request.
1Splunk
1Splunk
Jun 17, 2026
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light...Show more
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Splunk
1Splunk
Nov 21, 2024
Oct 19, 2018
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by leveraging access to that non-root account to modify $SPLUNK_HOME/etc/s...Show more
Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by leveraging access to that non-root account to modify $SPLUNK_HOME/etc/splunk-launch.conf and insert Trojan horse programs into $SPLUNK_HOME/bin, because the non-root setup instructions state that chown should be run across all of $SPLUNK_HOME to give non-root access.Show less
1Splunk
1Splunk
Nov 21, 2024
Jun 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.
1Splunk
1Splunk
May 13, 2026
Nov 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attacke...Show more
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intended access restrictions or conduct impersonation attacks.Show less
1Splunk
1Splunk
May 13, 2026
Aug 5, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-1...Show more
Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-134104.Show less
1Splunk
1Splunk
May 13, 2026
May 12, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x pri...Show more
Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x prior to 6.0.12, Splunk Enterprise 5.0.x prior to 5.0.16 and Splunk Light prior to 6.4.3 allows to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.Show less