Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Splunk — Vulnerabilities & Security Advisories 283

Browse all 283 CVE security advisories affecting Splunk. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Splunk operates primarily as a data analytics platform designed for searching, monitoring, and analyzing machine-generated big data via a web interface. Its architecture, which integrates complex data ingestion pipelines with extensive third-party app ecosystems, has historically exposed it to diverse vulnerability classes. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from improper input validation or insecure default configurations in its web components. While no single catastrophic breach defines its history, the sheer volume of disclosed flaws highlights systemic risks in its expansive feature set. Security practitioners must rigorously patch these instances, as the platform’s central role in enterprise observability makes unmitigated vulnerabilities particularly impactful. The current count of 155 CVEs underscores the necessity for continuous configuration auditing and strict access controls to maintain integrity within organizations relying on this infrastructure.

CVE ID Title CVSS Severity Published
CVE-2025-22621 Privilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAR — Splunk App for SOAR CWE-269 6.4 Medium 2025-01-07
CVE-2024-53244 Risky command safeguards bypass in “/en-US/app/search/report“ endpoint through “s“ parameter — Splunk Enterprise CWE-200 5.7 Medium 2024-12-10
CVE-2024-53246 Sensitive Information Disclosure through SPL commands — Splunk Enterprise CWE-319 5.3 Medium 2024-12-10
CVE-2024-53243 Information Disclosure in Mobile Alert Responses in Splunk Secure Gateway — Splunk Enterprise CWE-200 4.3 Medium 2024-12-10
CVE-2024-53245 Information Disclosure due to Username Collision with a Role that has the same Name as the User — Splunk Enterprise CWE-200 3.1 Low 2024-12-10
CVE-2024-53247 Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway app — Splunk Enterprise CWE-502 8.8 High 2024-12-10
CVE-2024-45739 Sensitive information disclosure in AdminManager logging channel — Splunk Enterprise CWE-200 4.9 Medium 2024-10-14
CVE-2024-45738 Sensitive information disclosure in REST_Calls logging channel — Splunk Enterprise CWE-200 4.9 Medium 2024-10-14
CVE-2024-45737 Maintenance mode state change of App Key Value Store (KVStore) through Cross-Site Request Forgery (CSRF) — Splunk Enterprise CWE-352 4.3 Medium 2024-10-14
CVE-2024-45732 Low-privileged user could run search as nobody in SplunkDeploymentServerConfig app — Splunk Enterprise CWE-862 7.1 High 2024-10-14
CVE-2024-45733 Remote Code Execution (RCE) due to insecure session storage configuration in Splunk Enterprise on Windows — Splunk Enterprise CWE-502 8.8 High 2024-10-14
CVE-2024-45736 Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon — Splunk Enterprise CWE-400 6.5 Medium 2024-10-14
CVE-2024-45741 Persistent Cross-Site Scripting (XSS) via props.conf on Splunk Enterprise — Splunk Enterprise CWE-79 5.4 Medium 2024-10-14
CVE-2024-45734 Low Privilege User can View Images on the Host Machine by using the PDF Export feature in Splunk Classic Dashboard — Splunk Enterprise CWE-284 4.3 Medium 2024-10-14
CVE-2024-45740 Persistent Cross-Site Scripting (XSS) through Scheduled Views on Splunk Enterprise — Splunk Enterprise CWE-79 5.4 Medium 2024-10-14
CVE-2024-45731 Potential Remote Command Execution (RCE) through arbitrary file write to Windows system root directory when Splunk Enterprise for Windows is installed on a separate disk — Splunk Enterprise CWE-23 8.0 High 2024-10-14
CVE-2024-45735 Improper Access Control for low-privileged user in Splunk Secure Gateway App — Splunk Enterprise CWE-284 4.3 Medium 2024-10-14
CVE-2024-36997 Persistent Cross-site Scripting (XSS) in conf-web/settings REST endpoint — Splunk Enterprise CWE-79 4.6 High 2024-07-01
CVE-2024-36993 Persistent Cross-site Scripting (XSS) in Web Bulletin — Splunk Enterprise CWE-79 5.4 Medium 2024-07-01
CVE-2024-36995 Low-privileged user could create experimental items — Splunk Enterprise CWE-862 4.3 Medium 2024-07-01
CVE-2024-36991 Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows — Splunk Enterprise CWE-35 7.5 High 2024-07-01
CVE-2024-36982 Denial of Service through null pointer reference in “cluster/config” REST endpoint — Splunk Enterprise CWE-476 7.5 High 2024-07-01
CVE-2024-36990 Denial of Service (DoS) on the datamodel/web REST endpoint — Splunk Enterprise CWE-835 6.5 Medium 2024-07-01
CVE-2024-36985 Remote Code Execution (RCE) through an external lookup due to “copybuckets.py“ script in the “splunk_archiver“ application in Splunk Enterprise — Splunk Enterprise CWE-687 8.8 High 2024-07-01
CVE-2024-36992 Persistent Cross-site Scripting (XSS) in Dashboard Elements — Splunk Enterprise CWE-79 5.4 Medium 2024-07-01
CVE-2024-36984 Remote Code Execution through Serialized Session Payload in Splunk Enterprise on Windows — Splunk Enterprise CWE-502 8.8 High 2024-07-01
CVE-2024-36983 Command Injection using External Lookups — Splunk Enterprise CWE-77 8.0 High 2024-07-01
CVE-2024-36986 Risky command safeguards bypass through Search ID query in Analytics Workspace — Splunk Enterprise CWE-200 6.3 Medium 2024-07-01
CVE-2024-36996 Information Disclosure of user names — Splunk Enterprise CWE-204 5.3 Medium 2024-07-01
CVE-2024-36994 Persistent Cross-site Scripting (XSS) in Dashboard Elements — Splunk Enterprise CWE-79 5.4 Medium 2024-07-01

This page lists every published CVE security advisory associated with Splunk. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.