Splunk Inc. maintains a broadly represented vulnerability footprint across a portfolio of data indexing, search, and analytics platforms that are deeply embedded in enterprise security, IT operations, and compliance workflows. The vendor's exposure concentrates in flagship products such as Splunk Enterprise, the Splunk Cloud Platform, and its Universal Forwarder component, serving a critical intelligence role across heterogeneous environments where vulnerabilities can affect both the collection and interpretation of security telemetry. The recurring weakness classes center on input-handling and path-traversal issues characteristic of web-facing applications and data-processing systems: cross-site scripting, input validation defects, path traversal, and information exposure, reflecting the vendor's broad surface as an aggregation and visualization platform. Defenders should prioritize Splunk advisories for environments where the platform serves as an observability backbone; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Splunk Inc. over time
Signals from CVEs in this vendor scope (276 CVEs).
276 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-20253CRITICAL In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service | Jun 10, 2026 | 9.8 | 99 | YES | YES |
CVE-2014-0160HIGH The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform | Apr 7, 2014 | 7.5 | 99 | YES | YES |
CVE-2018-11409MEDIUM Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key. | Jun 8, 2018 | 5.3 | 89 | NO | YES |
CVE-2023-46214HIGH In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means | Nov 16, 2023 | 8.8 | 84 | NO | YES |
CVE-2023-32707HIGH In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_us | Jun 1, 2023 | 8.8 | 84 | NO | YES |
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2011-4642MEDIUM mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators t | Jan 3, 2012 | 4.6 | 50 | NO | YES |
CVE-2022-43571HIGH In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
| Nov 3, 2022 | 8.8 | 48 | NO | YES |
CVE-2023-32714HIGH In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be u | Jun 1, 2023 | 8.1 | 47 | NO | NO |
CVE-2022-43568MEDIUM In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when out | Nov 4, 2022 | 6.1 | 43 | NO | NO |
Signals from CVEs in this vendor scope (276 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Splunk Inc..
Media articles that mention a CVE ID that affects a product developed by Splunk Inc. — matched by CVE ID, not by vendor name.