CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76405
4.3 MEDIUM

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a …

Aug 19, 2026
CVE-2026-76401
5.9 MEDIUM

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp …

Aug 19, 2026
CVE-2026-76400
5.9 MEDIUM

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses …

Aug 19, 2026
CVE-2026-76398
4.3 MEDIUM

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of …

Aug 19, 2026
CVE-2026-76393
5.9 MEDIUM

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a …

Aug 19, 2026
CVE-2026-76392
5.4 MEDIUM

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials …

Aug 19, 2026
CVE-2026-76390
5.3 MEDIUM

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file …

Aug 19, 2026
CVE-2026-76386
4.3 MEDIUM

In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting …

Aug 19, 2026
CVE-2026-76385
4.3 MEDIUM

In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore …

Aug 19, 2026
CVE-2026-76384
4.3 MEDIUM

In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could …

Aug 19, 2026
CVE-2026-76383
4.3 MEDIUM

In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions …

Aug 19, 2026
CVE-2026-76382
4.3 MEDIUM

In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a …

Aug 19, 2026
CVE-2026-76381
4.3 MEDIUM

In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run …

Aug 19, 2026
CVE-2026-76380
4.3 MEDIUM

In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could …

Aug 19, 2026
CVE-2026-76379
4.3 MEDIUM

In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose …

Aug 19, 2026
CVE-2026-76378
4.3 MEDIUM

In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions …

Aug 19, 2026
CVE-2026-76377
4.3 MEDIUM

In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could …

Aug 19, 2026
CVE-2026-76376
4.3 MEDIUM

In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could expose …

Aug 19, 2026
CVE-2026-76375
5.0 MEDIUM

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose …

Aug 19, 2026
CVE-2026-76374
4.3 MEDIUM

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause …

Aug 19, 2026
CVE-2026-76373
5.4 MEDIUM

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject …

Aug 19, 2026
CVE-2026-76372
6.6 MEDIUM

In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the …

Aug 19, 2026
CVE-2026-76370
4.3 MEDIUM

In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names …

Aug 19, 2026
CVE-2026-76367
4.0 MEDIUM

In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a note and run it …

Aug 19, 2026
CVE-2026-76366
6.5 MEDIUM

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs …

Aug 19, 2026
CVE-2026-76365
6.5 MEDIUM

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against …

Aug 19, 2026
CVE-2026-76364
6.5 MEDIUM

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against …

Aug 19, 2026
CVE-2026-76363
6.5 MEDIUM

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL) statements against the Splunk …

Aug 19, 2026
CVE-2026-76360
4.3 MEDIUM

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that …

Aug 19, 2026
CVE-2026-76359
6.5 MEDIUM

In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to …

Aug 19, 2026
CVE-2026-76358
6.5 MEDIUM

In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the intended temporary …

Aug 19, 2026
CVE-2026-76353
5.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a …

Aug 19, 2026
CVE-2026-76349
6.4 MEDIUM

In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running arbitrary Search Processing Language (SPL) commands …

Aug 19, 2026
CVE-2026-76347
5.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not …

Aug 19, 2026
CVE-2026-76346
5.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard …

Aug 19, 2026
CVE-2026-76345
6.0 MEDIUM

In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage search head clustering could use the search head cluster …

Aug 19, 2026
CVE-2026-76343
6.5 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute attacker-chosen …

Aug 19, 2026
CVE-2026-76342
5.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store risky Search Processing Language (SPL) …

Aug 19, 2026
CVE-2026-76341
5.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) …

Aug 19, 2026
CVE-2026-76340
5.3 MEDIUM

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. …

Aug 19, 2026
CVE-2026-76339
5.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject arbitrary …

Aug 19, 2026
CVE-2026-76337
5.3 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability …

Aug 19, 2026
CVE-2026-76334
6.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action …

Aug 19, 2026
CVE-2026-76329
6.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role into opening …

Aug 19, 2026
CVE-2026-76328
6.7 MEDIUM

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) …

Aug 19, 2026
CVE-2026-76327
6.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick …

Aug 19, 2026
CVE-2026-76326
5.7 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could store a …

Aug 19, 2026
CVE-2026-76324
5.7 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could create a malicious Splunk Web tour …

Aug 19, 2026
CVE-2026-76323
6.4 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could bypass Search …

Aug 19, 2026
CVE-2026-76322
6.7 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user" Splunk role could craft a Dashboard Studio dashboard that …

Aug 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.