Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sciencelogic

First CVE: Aug 9, 2023Active for: 3 yearsTotal CVEs: 27
67.6
VTI Score
TOP TARGET

Sciencelogic's vulnerability footprint centers on a narrowly scoped product line centered around its SL1 infrastructure monitoring and management platform, which serves as a critical integration point across enterprise IT environments. The exposure recurs through application-layer input-handling weaknesses, primarily OS command injection and SQL injection, reflecting the platform's role in collecting and processing data from diverse network and system sources. While the vendor has disclosed vulnerabilities across its monitoring platform, the durable signal is the parser and command-execution surface area inherent to comprehensive infrastructure management tools. Defenders should prioritize patching this vendor's releases given the privileged network context and data-aggregation function of SL1; current severity, exploitation activity, and CVE counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
9.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked vendors
3.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sciencelogic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 9, 2023
2 years ago
Most Recent CVE
Sep 5, 2025
322 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-9537CRITICAL
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1
Oct 18, 20249.871YESNO
CVE-2022-48599HIGH
A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL quer
Aug 9, 20238.827NONO
CVE-2022-48580HIGH
A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell
Aug 9, 20238.825NONO
CVE-2025-58780HIGH
index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately describes the vulnera
Sep 5, 20257.223NONO
CVE-2022-48604HIGH
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. Thi
Aug 9, 20238.823NONO
CVE-2022-48600HIGH
A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This al
Aug 9, 20238.823NONO
CVE-2022-48586HIGH
A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This a
Aug 9, 20238.823NONO
CVE-2022-48585HIGH
A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query.
Aug 9, 20238.823NONO
CVE-2022-48584HIGH
A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a
Aug 9, 20238.823NONO
CVE-2022-48581HIGH
A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command
Aug 9, 20238.823NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
96%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None27 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low25 (92.6%)
High0 (0.0%)
None2 (7.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
1 CVE
3.7% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sciencelogic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sciencelogic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sciencelogic's Products

View all 3 CNAs →

Top CWEs