VendorsSplunksplunk_cloud_platformany version
Vulnerabilities

Splunk Splunk Cloud Platform any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

109CVEs
CVE-2022-32151
Splunk Enterprise disabled TLS validation using the CA certificate stores in Python 3 libraries by default
Published 2022-06-15 · Modified
9.1EPSS 0.008
CVE-2023-32707
‘edit_user’ Capability Privilege Escalation
Published 2023-06-01 · Modified
8.81 PoCEPSS 0.790
CVE-2022-43568
Reflected Cross-Site Scripting via the radio template in Splunk Enterprise
Published 2022-11-04 · Modified
8.8EPSS 0.428
CVE-2026-20251
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
Published 2026-06-10 · Analyzed
8.8EPSS 0.322
CVE-2022-43571
Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
Published 2022-11-03 · Modified
8.8EPSS 0.138
CVE-2022-43567
Remote Code Execution via the Splunk Secure Gateway application Mobile Alerts feature
Published 2022-11-04 · Modified
8.8EPSS 0.013
CVE-2024-36983
Command Injection using External Lookups
Published 2024-07-01 · Analyzed
8.8EPSS 0.010
CVE-2023-40595
Remote Code Execution via Serialized Session Payload
Published 2023-08-30 · Modified
8.8EPSS 0.009
CVE-2023-40598
Command Injection in Splunk Enterprise Using External Lookups
Published 2023-08-30 · Modified
8.8EPSS 0.008
CVE-2023-32708
HTTP Response Splitting via the ‘rest’ SPL Command
Published 2023-06-01 · Modified
8.8EPSS 0.007
CVE-2022-43570
XML External Entity Injection through a custom View in Splunk Enterprise
Published 2022-11-04 · Modified
8.8EPSS 0.007
CVE-2022-43565
Risky command safeguards bypass via ‘tstats command JSON in Splunk Enterprise
Published 2022-11-04 · Modified
8.8EPSS 0.006
CVE-2022-43563
Risky command safeguards bypass via rex search command field names in Splunk Enterprise
Published 2022-11-04 · Modified
8.8EPSS 0.006
CVE-2023-22935
SPL Command Safeguards Bypass via the ‘display.page.search.patterns.sensitivity’ Search Parameter in Splunk Enterprise
Published 2023-02-14 · Modified
8.8EPSS 0.006
CVE-2023-22939
SPL Command Safeguards Bypass via the ‘map’ SPL Command in Splunk Enterprise
Published 2023-02-14 · Modified
8.8EPSS 0.006
CVE-2025-20371
Unauthenticated Blind Server Side Request Forgery (SSRF) in Splunk Enterprise
Published 2025-10-01 · Analyzed
8.8EPSS 0.005
CVE-2023-40597
Absolute Path Traversal in Splunk Enterprise Using runshellscript.py
Published 2023-08-30 · Modified
8.8EPSS 0.002
CVE-2023-22932
Persistent Cross-Site Scripting through a Base64-encoded Image in a View in Splunk Enterprise
Published 2023-02-14 · Modified
8.7EPSS 0.004
CVE-2023-40592
Reflected Cross-site Scripting (XSS) on "/app/search/table" web endpoint
Published 2023-08-30 · Modified
8.4EPSS 0.006
CVE-2026-20296
SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise
Published 2026-07-15 · Analyzed
8.3EPSS 0.002
CVE-2022-32154
Risky commands warnings in Splunk Enterprise Dashboards
Published 2022-06-15 · Modified
8.1EPSS 0.014
CVE-2022-32152
Splunk Enterprise lacked TLS cert validation for Splunk-to-Splunk communication by default
Published 2022-06-15 · Modified
8.1EPSS 0.009
CVE-2022-32153
Splunk Enterprise lacked TLS host name validation
Published 2022-06-15 · Modified
8.1EPSS 0.009
CVE-2024-36997
Persistent Cross-site Scripting (XSS) in conf-web/settings REST endpoint
Published 2024-07-01 · Analyzed
8.1EPSS 0.005
CVE-2025-20229
Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprise
Published 2025-03-26 · Analyzed
8.0EPSS 0.160
CVE-2023-22934
SPL Command Safeguards Bypass via the ‘pivot’ SPL Command in Splunk Enterprise
Published 2023-02-14 · Modified
8.0EPSS 0.011
CVE-2023-22933
Persistent Cross-Site Scripting through the ‘module’ Tag in a View in Splunk Enterprise
Published 2023-02-14 · Modified
8.0EPSS 0.008
CVE-2022-43566
Risky command safeguards bypass via Search ID query in Analytics Workspace in Splunk Enterprise
Published 2022-11-04 · Modified
8.0EPSS 0.008
CVE-2022-43569
Persistent Cross-Site Scripting via a Data Model object name in Splunk Enterprise
Published 2022-11-04 · Modified
8.0EPSS 0.007
CVE-2023-32706
Denial Of Service due to Untrusted XML Tag in XML Parser within SAML Authentication
Published 2023-06-01 · Modified
7.7EPSS 0.006
CVE-2026-20252
Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise
Published 2026-06-10 · Analyzed
7.6EPSS 0.003
CVE-2022-32155
Universal Forwarder management services allows remote login by default
Published 2022-06-15 · Modified
7.5EPSS 0.020
CVE-2023-22941
Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon
Published 2023-02-14 · Modified
7.5EPSS 0.010
CVE-2022-43572
Indexing blockage via malformed data sent through S2S or HEC protocols in Splunk Enterprise
Published 2022-11-04 · Modified
7.5EPSS 0.008
CVE-2023-40593
Denial of Service (DoS) in Splunk Enterprise Using a Malformed SAML Request
Published 2023-08-30 · Modified
7.5EPSS 0.006
CVE-2026-20239
Sensitive Information Disclosure through Log Files in Splunk Enterprise
Published 2026-05-20 · Analyzed
7.5EPSS 0.005
CVE-2023-40594
Denial of Service (DoS) via the ‘printf’ Search Function
Published 2023-08-30 · Modified
7.5EPSS 0.004
CVE-2024-53246
Sensitive Information Disclosure through SPL commands
Published 2024-12-10 · Analyzed
7.5EPSS 0.003
CVE-2025-20320
Denial of Service (DoS) through “User Interface - Views“ configuration page in Splunk Enterprise
Published 2025-07-07 · Analyzed
7.3EPSS 0.004
CVE-2026-20297
Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
Published 2026-07-15 · Analyzed
7.2EPSS 0.006
1 / 3Next →