Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Splunk Inc.

First CVE: Jun 24, 2010Active for: 16 yearsTotal CVEs: 276
59.9
VTI Score
TOP TARGET

Splunk Inc. maintains a broadly represented vulnerability footprint across a portfolio of data indexing, search, and analytics platforms that are deeply embedded in enterprise security, IT operations, and compliance workflows. The vendor's exposure concentrates in flagship products such as Splunk Enterprise, the Splunk Cloud Platform, and its Universal Forwarder component, serving a critical intelligence role across heterogeneous environments where vulnerabilities can affect both the collection and interpretation of security telemetry. The recurring weakness classes center on input-handling and path-traversal issues characteristic of web-facing applications and data-processing systems: cross-site scripting, input validation defects, path traversal, and information exposure, reflecting the vendor's broad surface as an aggregation and visualization platform. Defenders should prioritize Splunk advisories for environments where the platform serves as an observability backbone; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
276
Total CVEs
More Total CVEs than 100% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Splunk Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2010
16 years ago
Most Recent CVE
Jun 17, 2026
37 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (276 CVEs).

276 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-20253CRITICAL
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service
Jun 10, 20269.899YESYES
CVE-2014-0160HIGH
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES
CVE-2018-11409MEDIUM
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.
Jun 8, 20185.389NOYES
CVE-2023-46214HIGH
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means
Nov 16, 20238.884NOYES
CVE-2023-32707HIGH
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_us
Jun 1, 20238.884NOYES
CVE-2021-22901HIGH
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic
Jun 11, 20218.160NONO
CVE-2011-4642MEDIUM
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators t
Jan 3, 20124.650NOYES
CVE-2022-43571HIGH
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
Nov 3, 20228.848NOYES
CVE-2023-32714HIGH
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be u
Jun 1, 20238.147NONO
CVE-2022-43568MEDIUM
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when out
Nov 4, 20226.143NONO
View all 276 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products276 CVEs
56%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (5.1%)
Network232 (84.1%)
Unknown27 (9.8%)
Physical0 (0.0%)
Adjacent Network3 (1.1%)
Attack Complexity
Low223 (80.8%)
High26 (9.4%)
Unknown27 (9.8%)
User Interaction
None162 (58.7%)
Unknown27 (9.8%)
Required87 (31.5%)
Privileges Required
Low118 (42.8%)
High23 (8.3%)
None108 (39.1%)
Unknown27 (9.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (276 CVEs).

CISA KEV
2 CVEs
0.7% of CVEs· 99th percentile
Metasploit
7 CVEs
2.5% of CVEs· 97th percentile
Nuclei
4 CVEs
1.4% of CVEs· 95th percentile
ExploitDB
8 CVEs
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Splunk Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Splunk Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Splunk Inc.'s Products

View all 7 CNAs →

Top CWEs