Sl1
Vendor:
First CVE: Aug 9, 2023 · Active for 2 years
27
Total CVEs
More Total CVEs than 96% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 79% of tracked products
3.7%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sl1 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 9, 2023
2 years ago
Most Recent CVE
Sep 5, 2025
324 days ago
CVE Severity & Scoring
Sl127 CVEs
96%
All CVEs352,719 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None27 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low25 (92.6%)
High0 (0.0%)
None2 (7.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9537CRITICAL ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 | Oct 18, 2024 | 9.8 | 71 | YES | NO |
CVE-2022-48599HIGH A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL quer | Aug 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-48580HIGH A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell | Aug 9, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-58780HIGH index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately describes the vulnera | Sep 5, 2025 | 7.2 | 23 | NO | NO |
CVE-2022-48604HIGH A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. Thi | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48600HIGH A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This al | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48586HIGH A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This a | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48585HIGH A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48584HIGH A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a | Aug 9, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-48581HIGH A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command | Aug 9, 2023 | 8.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
1 CVE
3.7% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Sl1
Top CWEs
Versions
No cataloged versions.