Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

398 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)43%—SplunkSplunk Cloud Platform4/11/202217/6/2026
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.
ModificadaAlta (8.8)1.3%—SplunkSplunk Cloud Platform4/11/202217/6/2026
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.
ModificadaAlta (8)0.82%—SplunkSplunk Cloud Platform4/11/202217/6/2026
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions to bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards in the Analytics Workspace. The vulnerability…
ModificadaAlta (8.8)0.64%—SplunkSplunk Cloud Platform4/11/202217/6/2026
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish…
ModificadaMedia (6.5)0.85%—SplunkSplunk Cloud Platform4/11/202217/6/2026
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a denial of service through the use of specially crafted search macros.
ModificadaAlta (8.8)0.64%—SplunkSplunk Cloud Platform4/11/202217/6/2026
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by…
ModificadaMedia (5.4)0.44%—SplunkSplunk Cloud Platform4/11/202217/6/2026
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.
ModificadaAlta (8.8)14%💥 ExploitSplunkSplunk Cloud Platform3/11/202217/6/2026
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
ModificadaMedia (4.8)0.66%—SplunkSplunk Cloud Platform3/11/202217/6/2026
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.
ModificadaAlta (8.1)2.9%—Haxx CurlFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+529/10/202217/6/2026
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only…
ModificadaAlta (7.5)1.8%—Haxx CurlFedoraproject FedoraApple MacosSplunk Universal Forwarder29/10/202217/6/2026
In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL…
ModificadaBaja (3.7)2.4%—Haxx CurlNetapp Clustered Data OntapNetapp Element SoftwareNetapp HCI Management Node+923/9/202217/6/2026
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
ModificadaAlta (7.8)0.39%—LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+1023/8/202217/6/2026
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may…
ModificadaMedia (5.5)0.20%—SplunkSplunk Universal Forwarder16/8/202217/6/2026
In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually removing the malformed file.
ModificadaBaja (3.5)0.51%—SplunkSplunk Cloud Platform16/8/202217/6/2026
In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially leak information (for example, username, email, and real name) about Splunk users, when visited by another user through the drilldown component. The vulnerability requires user access to create and…
ModificadaCrítica (9.8)0.44%—Splunk16/8/202217/6/2026
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and an Ingest Actions Destination through…
ModificadaAlta (7.5)23%💥 PoCSqliteNetapp Ontap Select Deploy Administration UtilitySplunk Universal Forwarder3/8/202217/6/2026
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
ModificadaMedia (5.9)7.5%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+107/7/202217/6/2026
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
ModificadaCrítica (9.8)7.7%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+107/7/202217/6/2026
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file…
ModificadaMedia (6.5)33%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+157/7/202217/6/2026
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of…
ModificadaMedia (4.3)28%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+157/7/202217/6/2026
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold…
ModificadaCrítica (10)1.4%—Splunk15/6/202217/6/2026
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal…
ModificadaAlta (7.5)1.3%—Splunk15/6/202217/6/2026
Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients…
ModificadaAlta (8.1)0.80%—SplunkSplunk Universal Forwarder15/6/202217/6/2026
In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configure TLS host name validation for the Splunk CLI…
ModificadaAlta (7.5)2.0%—SplunkSplunk Cloud Platform15/6/202217/6/2026
In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your environment. In 9.0, the universal forwarder now…
Orbitaley — Vulnerabilidades