VendorsSplunksplunk_cloud_platformall versions
Vulnerabilities

Splunk Splunk Cloud Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

109CVEs
CVE-2024-36992
Persistent Cross-site Scripting (XSS) in Dashboard Elements
Published 2024-07-01 · Modified
5.4EPSS 0.003
CVE-2024-36994
Persistent Cross-site Scripting (XSS) in Dashboard Elements
Published 2024-07-01 · Modified
5.4EPSS 0.003
CVE-2025-20324
Improper Access Control in System Source Types Configuration in Splunk Enterprise
Published 2025-07-07 · Analyzed
5.4EPSS 0.002
CVE-2025-20382
URL validation bypass through Views Dashboard in Splunk Enterprise
Published 2025-12-03 · Analyzed
5.4EPSS 0.002
CVE-2024-36995
Low-privileged user could create experimental items
Published 2024-07-01 · Modified
5.4EPSS 0.002
CVE-2026-20166
Sensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk Enterprise
Published 2026-03-11 · Analyzed
5.4EPSS 0.002
CVE-2023-32710
Information Disclosure via the ‘copyresults’ SPL Command
Published 2023-06-01 · Modified
5.3EPSS 0.004
CVE-2025-20384
Unauthenticated Log Injection in Splunk Enterprise
Published 2025-12-03 · Analyzed
5.3EPSS 0.004
CVE-2024-36996
Information Disclosure of user names
Published 2024-07-01 · Modified
5.3EPSS 0.004
CVE-2025-20325
Sensitive Information Disclosure in the SHCConfig logging channel in Clustered Deployments in Splunk Enterprise
Published 2025-07-07 · Analyzed
5.3EPSS 0.003
CVE-2025-20370
Denial of Service (DoS) through Multiple LDAP Bind Requests in Splunk Enterprise
Published 2025-10-01 · Analyzed
4.9EPSS 0.006
CVE-2025-20385
Stored Cross-Site scripting (XSS) through Anchor Tag "href" in Navigation Bar Collections in Splunk Enterprise
Published 2025-12-03 · Analyzed
4.8EPSS 0.003
CVE-2026-20139
Client-Side Denial of Service (DoS) through ''/splunkd/__raw/services/authentication/users/username'' REST API endpoint in Splunk Enterprise
Published 2026-02-18 · Analyzed
4.3EPSS 0.050
CVE-2023-22937
Unnecessary File Extensions Allowed by Lookup Table Uploads in Splunk Enterprise
Published 2023-02-14 · Modified
4.3EPSS 0.004
CVE-2025-20227
Information Disclosure through external content warning modal dialog box bypass in Splunk Enterprise Dashboard Studio
Published 2025-03-26 · Analyzed
4.3EPSS 0.004
CVE-2023-32709
Low-privileged User can View Hashed Default Splunk Password
Published 2023-06-01 · Modified
4.3EPSS 0.004
CVE-2024-53245
Information Disclosure due to Username Collision with a Role that has the same Name as the User
Published 2024-12-10 · Analyzed
4.3EPSS 0.004
CVE-2023-32717
Role-based Access Control (RBAC) Bypass on '/services/indexing/preview' REST Endpoint Can Overwrite Search Results
Published 2023-06-01 · Modified
4.3EPSS 0.004
CVE-2023-22931
‘createrss’ External Search Command Overwrites Existing RSS Feeds in Splunk Enterprise
Published 2023-02-14 · Modified
4.3EPSS 0.004
CVE-2023-22938
Permissions Validation Failure in the ‘sendemail’ REST API Endpoint in Splunk Enterprise
Published 2023-02-14 · Modified
4.3EPSS 0.004
CVE-2024-45735
Improper Access Control for low-privileged user in Splunk Secure Gateway App
Published 2024-10-14 · Analyzed
4.3EPSS 0.003
CVE-2025-20383
Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app
Published 2025-12-03 · Analyzed
4.3EPSS 0.003
CVE-2025-20300
Improper Access Control Lets Low-Privilege Users Suppress Read-Only Alerts in Splunk Enterprise
Published 2025-07-07 · Analyzed
4.3EPSS 0.003
CVE-2024-45737
Maintenance mode state change of App Key Value Store (KVStore) through Cross-Site Request Forgery (CSRF)
Published 2024-10-14 · Analyzed
4.3EPSS 0.002
CVE-2025-20322
Denial of Service (DoS) in Search Head Cluster through Cross-Site Request Forgery (CSRF) in Splunk Enterprise
Published 2025-07-07 · Analyzed
4.3EPSS 0.002
CVE-2026-20203
Improper Access Control in Data Model Acceleration in Splunk Enterprise
Published 2026-04-15 · Analyzed
4.3EPSS 0.002
CVE-2022-37438
Information disclosure via the dashboard drilldown in Splunk Enterprise
Published 2022-08-16 · Modified
3.5EPSS 0.005
CVE-2025-20379
Risky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk Enterprise
Published 2025-11-12 · Analyzed
3.5EPSS 0.003
CVE-2025-20388
Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise
Published 2025-12-03 · Analyzed
2.7EPSS 0.004
← Prev3 / 3