VendorsSplunksplunk_cloud_platformany version
Vulnerabilities

Splunk Splunk Cloud Platform any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

109CVEs
CVE-2026-20163
Remote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk Enterprise
Published 2026-03-11 · Analyzed
7.2EPSS 0.005
CVE-2026-20204
Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise
Published 2026-04-15 · Analyzed
7.1EPSS 0.031
CVE-2024-45732
Low-privileged user could run search as nobody in SplunkDeploymentServerConfig app
Published 2024-10-14 · Analyzed
7.1EPSS 0.004
CVE-2026-20258
Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise
Published 2026-06-10 · Analyzed
7.1EPSS 0.002
CVE-2026-20144
Sensitive Information Disclosure in ''_internal'' index in Splunk Enterprise
Published 2026-02-18 · Analyzed
6.8EPSS 0.004
CVE-2026-20202
Improper Input Validation during User Account Creation in Splunk Enterprise
Published 2026-04-15 · Analyzed
6.6EPSS 0.002
CVE-2022-43564
Denial of Service in Splunk Enterprise through search macros
Published 2022-11-04 · Modified
6.5EPSS 0.008
CVE-2024-36990
Denial of Service (DoS) on the datamodel/web REST endpoint
Published 2024-07-01 · Modified
6.5EPSS 0.007
CVE-2023-32716
Denial of Service via the 'dump' SPL command
Published 2023-06-01 · Modified
6.5EPSS 0.006
CVE-2024-45736
Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon
Published 2024-10-14 · Analyzed
6.5EPSS 0.005
CVE-2025-20366
Improper Access Control in Background Job Submission in Splunk Enterprise
Published 2025-10-01 · Analyzed
6.5EPSS 0.004
CVE-2025-20389
Improper Input Validation in "label" column field in Splunk Secure Gateway App
Published 2025-12-03 · Analyzed
6.5EPSS 0.004
CVE-2026-20240
Denial of Service through coldToFrozen.sh Script in Splunk Enterprise
Published 2026-05-20 · Analyzed
6.5EPSS 0.004
CVE-2026-20298
Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise
Published 2026-07-15 · Analyzed
6.5EPSS 0.003
CVE-2025-20369
Extensible Markup Language (XML) External Entity Injection (XXE) through Dashboard label field on Splunk Enterprise
Published 2025-10-01 · Analyzed
6.5EPSS 0.003
CVE-2026-20164
Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise
Published 2026-03-11 · Analyzed
6.5EPSS 0.002
CVE-2025-20228
Maintenance mode state change of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF) in Splunk Enterprise
Published 2025-03-26 · Analyzed
6.5EPSS 0.002
CVE-2025-20321
Membership State Change in Splunk Search Head Cluster through a Cross-Site Request Forgery (CSRF) in Splunk Enterprise
Published 2025-07-07 · Analyzed
6.5EPSS 0.002
CVE-2026-20165
Sensitive Information Disclosure in MongoClient logging channel in Splunk Enterprise
Published 2026-03-11 · Analyzed
6.5EPSS 0.002
CVE-2022-43561
Persistent Cross-Site Scripting in “Save Table” Dialog in Splunk Enterprise
Published 2022-11-03 · Modified
6.4EPSS 0.007
CVE-2023-22940
SPL Command Safeguards Bypass via the ‘collect’ SPL Command Aliases in Splunk Enterprise
Published 2023-02-14 · Modified
6.3EPSS 0.004
CVE-2023-22936
Authenticated Blind Server Side Request Forgery via the ‘search_listener’ Search Parameter in Splunk Enterprise
Published 2023-02-14 · Modified
6.3EPSS 0.004
CVE-2026-20162
Stored Cross-Site Scripting (XSS) through Path Traversal in Splunk Enterprise
Published 2026-03-11 · Analyzed
6.3EPSS 0.002
CVE-2025-20378
Open Redirect on Web Login endpoint in Splunk Enterprise
Published 2025-11-12 · Analyzed
6.1EPSS 0.002
CVE-2024-53244
Risky command safeguards bypass in “/en-US/app/search/report“ endpoint through “s“ parameter
Published 2024-12-10 · Analyzed
5.7EPSS 0.005
CVE-2025-20232
Risky Command Safeguards Bypass in “/app/search/search“ endpoint through “s“ parameter in Splunk Enterprise
Published 2025-03-26 · Analyzed
5.7EPSS 0.005
CVE-2025-20226
Risky command safeguards bypass in “/services/streams/search“ endpoint through “q“ parameter in Splunk Enterprise
Published 2025-03-26 · Analyzed
5.7EPSS 0.005
CVE-2026-20254
Information Disclosure through External Content Restriction Bypass in Splunk Enterprise
Published 2026-06-10 · Analyzed
5.7EPSS 0.004
CVE-2026-20256
Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise
Published 2026-06-10 · Analyzed
5.7EPSS 0.004
CVE-2025-20367
Reflected Cross-site Scripting (XSS) in '/app/search/table' endpoint through the 'dataset.command' parameter on Splunk Enterprise
Published 2025-10-01 · Analyzed
5.7EPSS 0.004
CVE-2025-20368
Stored Cross-Site Scripting (XSS) through missing field warning messages in Saved Search and Job Inspector on Splunk Enterprise
Published 2025-10-01 · Analyzed
5.7EPSS 0.004
CVE-2026-20255
Improper Input Validation through Classic Dashboards in Splunk Enterprise
Published 2026-06-10 · Analyzed
5.7EPSS 0.004
CVE-2026-20257
Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise
Published 2026-06-10 · Analyzed
5.7EPSS 0.003
CVE-2026-20137
Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk Enterprise
Published 2026-02-18 · Analyzed
5.7EPSS 0.002
CVE-2026-20259
Improper Access Control in Splunk Enterprise
Published 2026-06-10 · Analyzed
5.5EPSS 0.002
CVE-2025-20297
Reflected Cross-Site Scripting (XSS) on Splunk Enterprise through dashboard PDF generation component
Published 2025-06-02 · Analyzed
5.4EPSS 0.259
CVE-2024-45741
Persistent Cross-Site Scripting (XSS) via props.conf on Splunk Enterprise
Published 2024-10-14 · Analyzed
5.4EPSS 0.148
CVE-2022-43562
Host Header Injection in Splunk Enterprise
Published 2022-11-04 · Modified
5.4EPSS 0.004
CVE-2024-36993
Persistent Cross-site Scripting (XSS) in Web Bulletin
Published 2024-07-01 · Modified
5.4EPSS 0.004
CVE-2024-45740
Persistent Cross-Site Scripting (XSS) through Scheduled Views on Splunk Enterprise
Published 2024-10-14 · Analyzed
5.4EPSS 0.004
← Prev2 / 3Next →