VendorsSplunkcloudall versions
Vulnerabilities

Splunk Cloud

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-46214
Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
Published 2023-11-16 · Modified
8.8EPSS 0.892
CVE-2024-36982
Denial of Service through null pointer reference in “cluster/config” REST endpoint
Published 2024-07-01 · Modified
7.5EPSS 0.005
CVE-2024-36989
Low-privileged user could create notifications in Splunk Web Bulletin Messages
Published 2024-07-01 · Modified
7.1EPSS 0.003
CVE-2024-23675
Splunk App Key Value Store (KV Store) Improper Handling of Permissions Leads to KV Store Collection Deletion
Published 2024-01-22 · Modified
6.5EPSS 0.004
CVE-2024-36987
Insecure File Upload in the indexing/preview REST endpoint
Published 2024-07-01 · Modified
6.5EPSS 0.003
CVE-2024-36986
Risky command safeguards bypass through Search ID query in Analytics Workspace
Published 2024-07-01 · Modified
6.3EPSS 0.004
CVE-2024-23677
Server Response Disclosure in RapidDiag Salesforce.com Log File
Published 2024-01-22 · Modified
5.3EPSS 0.004
CVE-2023-46213
Cross-site Scripting (XSS) on “Show Syntax Highlighted” View in Search Page
Published 2023-11-16 · Modified
4.8EPSS 0.005
CVE-2024-23676
Sensitive Information Disclosure of Index Metrics through “mrollup” SPL Command
Published 2024-01-22 · Modified
4.6EPSS 0.003