Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76336 | HIGH | 7.1 | In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing … | Aug 19, 2026 |
| CVE-2026-76335 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write … | Aug 19, 2026 |
| CVE-2026-76334 | MEDIUM | 6.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action … | Aug 19, 2026 |
| CVE-2026-76333 | HIGH | 7.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action … | Aug 19, 2026 |
| CVE-2026-76332 | HIGH | 7.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Analytics … | Aug 19, 2026 |
| CVE-2026-76331 | HIGH | 8.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject Search … | Aug 19, 2026 |
| CVE-2026-76330 | HIGH | 7.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring … | Aug 19, 2026 |
| CVE-2026-76329 | MEDIUM | 6.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role into opening … | Aug 19, 2026 |
| CVE-2026-76328 | MEDIUM | 6.7 | In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) … | Aug 19, 2026 |
| CVE-2026-76327 | MEDIUM | 6.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick … | Aug 19, 2026 |
| CVE-2026-76326 | MEDIUM | 5.7 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could store a … | Aug 19, 2026 |
| CVE-2026-76325 | HIGH | 7.3 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour knowledge object … | Aug 19, 2026 |
| CVE-2026-76324 | MEDIUM | 5.7 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could create a malicious Splunk Web tour … | Aug 19, 2026 |
| CVE-2026-76323 | MEDIUM | 6.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could bypass Search … | Aug 19, 2026 |
| CVE-2026-76322 | MEDIUM | 6.7 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user" Splunk role could craft a Dashboard Studio dashboard that … | Aug 19, 2026 |
| CVE-2026-76321 | HIGH | 7.3 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could inject arbitrary Search Processing Language (SPL) into requests that search for … | Aug 19, 2026 |
| CVE-2026-76320 | MEDIUM | 5.9 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authenticated user to run arbitrary Search Processing Language (SPL) … | Aug 19, 2026 |
| CVE-2026-76319 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution … | Aug 19, 2026 |
| CVE-2026-76318 | MEDIUM | 5.7 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could store a malicious script … | Aug 19, 2026 |
| CVE-2026-76317 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could move files … | Aug 19, 2026 |
| CVE-2026-76316 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port could store a Search Processing … | Aug 19, 2026 |
| CVE-2026-76315 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute arbitrary … | Aug 19, 2026 |
| CVE-2026-76314 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote … | Aug 19, 2026 |
| CVE-2026-76313 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote … | Aug 19, 2026 |
| CVE-2026-76312 | CRITICAL | 9.4 | In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page … | Aug 19, 2026 |