Sl1

Vendor:

First CVE: Aug 9, 2023 · Active for 2 years

27
Total CVEs
More Total CVEs than 96% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 79% of tracked products
3.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sl1 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 9, 2023
2 years ago
Most Recent CVE
Sep 5, 2025
324 days ago

CVE Severity & Scoring

Sl127 CVEs
All CVEs352,719 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None27 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low25 (92.6%)
High0 (0.0%)
None2 (7.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1
Oct 18, 20249.871YESNO
A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL quer
Aug 9, 20238.827NONO
A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell
Aug 9, 20238.825NONO
index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately describes the vulnera
Sep 5, 20257.223NONO
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. Thi
Aug 9, 20238.823NONO
A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This al
Aug 9, 20238.823NONO
A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This a
Aug 9, 20238.823NONO
A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query.
Aug 9, 20238.823NONO
A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a
Aug 9, 20238.823NONO
A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command
Aug 9, 20238.823NONO

Exploit Exposure

Signals from CVEs in this product scope (27 CVEs).

CISA KEV
1 CVE
3.7% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (27 CVEs).

Media Mentions

Signals from CVEs in this product scope (27 CVEs).

Top CNAs Publishing CVEs For Sl1

Top CWEs

Versions

No cataloged versions.