Sciencelogic's vulnerability footprint centers on a narrowly scoped product line centered around its SL1 infrastructure monitoring and management platform, which serves as a critical integration point across enterprise IT environments. The exposure recurs through application-layer input-handling weaknesses, primarily OS command injection and SQL injection, reflecting the platform's role in collecting and processing data from diverse network and system sources. While the vendor has disclosed vulnerabilities across its monitoring platform, the durable signal is the parser and command-execution surface area inherent to comprehensive infrastructure management tools. Defenders should prioritize patching this vendor's releases given the privileged network context and data-aggregation function of SL1; current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sciencelogic over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9537CRITICAL ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 | Oct 18, 2024 | 9.8 | 71 | YES | NO |
CVE-2022-48599HIGH A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL quer | Aug 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-48580HIGH A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell | Aug 9, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-58780HIGH index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately describes the vulnera | Sep 5, 2025 | 7.2 | 23 | NO | NO |
CVE-2022-48604HIGH A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. Thi | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48600HIGH A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This al | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48586HIGH A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This a | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48585HIGH A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48584HIGH A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48581HIGH A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command | Aug 9, 2023 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sciencelogic.
Media articles that mention a CVE ID that affects a product developed by Sciencelogic — matched by CVE ID, not by vendor name.