Перейти к содержимому
Noroxi

Записи ScienceLogic

26 опубликованных записей вендора sciencelogic.

Профиль для исследователя

Попали в KEV
1 · 3,8 %
С эксплойтом
1 · 3,8 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
3 дн.

Записи по годам

  1. 23
  2. 24

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

26 записей
  • CVE-2024-9537
    68На этой неделе

    ScienceLogic SL1 unspecified vulnerability

    КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 4 %

    sciencelogic · sl118 окт. 2024 г.

  • CVE-2022-48581
    35Наблюдать

    A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48582
    35Наблюдать

    A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlle

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48583
    35Наблюдать

    A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48584
    35Наблюдать

    A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐cont

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48580
    35Наблюдать

    A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48585
    35Наблюдать

    A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inpu

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48587
    35Наблюдать

    A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48604
    35Наблюдать

    A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input an

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48586
    35Наблюдать

    A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and p

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48589
    35Наблюдать

    A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled in

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48590
    35Наблюдать

    A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐contr

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48591
    35Наблюдать

    A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes u

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48592
    35Наблюдать

    A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48594
    35Наблюдать

    A SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48595
    35Наблюдать

    A SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlle

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48596
    35Наблюдать

    A SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48597
    35Наблюдать

    A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inp

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48598
    35Наблюдать

    A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controll

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48599
    35Наблюдать

    A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled in

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48600
    35Наблюдать

    A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and pa

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48601
    35Наблюдать

    A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled in

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48602
    35Наблюдать

    A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled in

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48603
    35Наблюдать

    A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.

  • CVE-2022-48588
    35Наблюдать

    A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controll

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sciencelogic · sl19 авг. 2023 г.