diff --git a/advisories/unreviewed/2024/06/GHSA-22p6-c9vr-pq5x/GHSA-22p6-c9vr-pq5x.json b/advisories/unreviewed/2024/06/GHSA-22p6-c9vr-pq5x/GHSA-22p6-c9vr-pq5x.json new file mode 100644 index 00000000000..759282475da --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-22p6-c9vr-pq5x/GHSA-22p6-c9vr-pq5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22p6-c9vr-pq5x", + "modified": "2024-06-02T15:30:37Z", + "published": "2024-06-02T15:30:37Z", + "aliases": [ + "CVE-2024-36392" + ], + "details": "MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36392" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-53mw-3q46-v8vp/GHSA-53mw-3q46-v8vp.json b/advisories/unreviewed/2024/06/GHSA-53mw-3q46-v8vp/GHSA-53mw-3q46-v8vp.json new file mode 100644 index 00000000000..40f8de2bd9b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-53mw-3q46-v8vp/GHSA-53mw-3q46-v8vp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53mw-3q46-v8vp", + "modified": "2024-06-02T15:30:37Z", + "published": "2024-06-02T15:30:37Z", + "aliases": [ + "CVE-2024-36390" + ], + "details": "MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36390" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5h7p-2q7c-v7w8/GHSA-5h7p-2q7c-v7w8.json b/advisories/unreviewed/2024/06/GHSA-5h7p-2q7c-v7w8/GHSA-5h7p-2q7c-v7w8.json new file mode 100644 index 00000000000..b1ac1fc9700 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5h7p-2q7c-v7w8/GHSA-5h7p-2q7c-v7w8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h7p-2q7c-v7w8", + "modified": "2024-06-02T15:30:37Z", + "published": "2024-06-02T15:30:37Z", + "aliases": [ + "CVE-2024-36391" + ], + "details": "MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36391" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g93h-34rm-55x7/GHSA-g93h-34rm-55x7.json b/advisories/unreviewed/2024/06/GHSA-g93h-34rm-55x7/GHSA-g93h-34rm-55x7.json new file mode 100644 index 00000000000..d8babb9e8e7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g93h-34rm-55x7/GHSA-g93h-34rm-55x7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g93h-34rm-55x7", + "modified": "2024-06-02T15:30:36Z", + "published": "2024-06-02T15:30:36Z", + "aliases": [ + "CVE-2024-27776" + ], + "details": "MileSight DeviceHub - \n\nCWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27776" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-02T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gcp5-jr9j-3744/GHSA-gcp5-jr9j-3744.json b/advisories/unreviewed/2024/06/GHSA-gcp5-jr9j-3744/GHSA-gcp5-jr9j-3744.json new file mode 100644 index 00000000000..ba7f6bcb30e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gcp5-jr9j-3744/GHSA-gcp5-jr9j-3744.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcp5-jr9j-3744", + "modified": "2024-06-02T15:30:37Z", + "published": "2024-06-02T15:30:37Z", + "aliases": [ + "CVE-2024-5588" + ], + "details": "A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266839.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5588" + }, + { + "type": "WEB", + "url": "https://github.com/Lanxiy7th/lx_CVE_report-/issues/12" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.266839" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.266839" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.347576" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-02T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mwjr-jwf4-2g7p/GHSA-mwjr-jwf4-2g7p.json b/advisories/unreviewed/2024/06/GHSA-mwjr-jwf4-2g7p/GHSA-mwjr-jwf4-2g7p.json new file mode 100644 index 00000000000..b63bb116235 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mwjr-jwf4-2g7p/GHSA-mwjr-jwf4-2g7p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwjr-jwf4-2g7p", + "modified": "2024-06-02T15:30:37Z", + "published": "2024-06-02T15:30:36Z", + "aliases": [ + "CVE-2024-36389" + ], + "details": "MileSight DeviceHub - \n\n\n\n\n\nCWE-330 Use of Insufficiently Random Values may allow Authentication Bypass", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36389" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-330" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-02T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v38j-rpc7-4g25/GHSA-v38j-rpc7-4g25.json b/advisories/unreviewed/2024/06/GHSA-v38j-rpc7-4g25/GHSA-v38j-rpc7-4g25.json new file mode 100644 index 00000000000..cbb769512fc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v38j-rpc7-4g25/GHSA-v38j-rpc7-4g25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v38j-rpc7-4g25", + "modified": "2024-06-02T15:30:36Z", + "published": "2024-06-02T15:30:36Z", + "aliases": [ + "CVE-2024-36388" + ], + "details": "MileSight DeviceHub - \n\n\n\nCWE-305 Missing Authentication for Critical Function", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36388" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-02T14:15:08Z" + } +} \ No newline at end of file