Записи ScienceLogic
26 опубликованных записей вендора sciencelogic.
Профиль для исследователя
- Попали в KEV
- 1 · 3,8 %
- С эксплойтом
- 1 · 3,8 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 3 дн.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2024-9537Готовый эксплойт | ScienceLogic SL1 unspecified vulnerabilitysciencelogic · sl1 | Критическая9,3 | KEV | 3,8 % | 18 окт. 2024 г. |
35Наблюдать | CVE-2022-48581Эксплойта нет | A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input asciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 1,6 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48582Эксплойта нет | A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controllesciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 1,6 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48583Эксплойта нет | A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled isciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 1,6 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48584Эксплойта нет | A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐contsciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 1,6 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48580Эксплойта нет | A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled sciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 1,5 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48585Эксплойта нет | A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inpusciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48587Эксплойта нет | A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input asciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48604Эксплойта нет | A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input ansciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48586Эксплойта нет | A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and psciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48589Эксплойта нет | A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled insciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48590Эксплойта нет | A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐contrsciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48591Эксплойта нет | A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes usciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48592Эксплойта нет | A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takessciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48594Эксплойта нет | A SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled isciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48595Эксплойта нет | A SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controllesciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48596Эксплойта нет | A SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled isciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48597Эксплойта нет | A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inpsciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48598Эксплойта нет | A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controllsciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48599Эксплойта нет | A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled insciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48600Эксплойта нет | A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and pasciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48601Эксплойта нет | A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled insciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48602Эксплойта нет | A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled insciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48603Эксплойта нет | A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled isciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
35Наблюдать | CVE-2022-48588Эксплойта нет | A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controllsciencelogic · sl1 · CWE-78 | Высокая8,8 | — | 0,7 % | 9 авг. 2023 г. |
- CVE-2024-953768На этой неделе
ScienceLogic SL1 unspecified vulnerability
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 4 %sciencelogic · sl118 окт. 2024 г.
- CVE-2022-4858135Наблюдать
A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input a
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858235Наблюдать
A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlle
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858335Наблюдать
A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled i
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858435Наблюдать
A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐cont
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858035Наблюдать
A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858535Наблюдать
A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inpu
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858735Наблюдать
A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input a
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4860435Наблюдать
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input an
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858635Наблюдать
A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and p
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858935Наблюдать
A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled in
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859035Наблюдать
A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐contr
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859135Наблюдать
A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes u
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859235Наблюдать
A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859435Наблюдать
A SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled i
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859535Наблюдать
A SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlle
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859635Наблюдать
A SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled i
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859735Наблюдать
A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inp
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859835Наблюдать
A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controll
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4859935Наблюдать
A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled in
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4860035Наблюдать
A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and pa
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4860135Наблюдать
A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled in
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4860235Наблюдать
A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled in
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4860335Наблюдать
A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled i
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.
- CVE-2022-4858835Наблюдать
A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controll
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sciencelogic · sl19 авг. 2023 г.