CVE-2024-9265

CRITICAL Year: 2024
CVSS v3 Score
9.8
Critical

Vulnerability Description

The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for unauthenticated attackers to register as an administrator.

CVSS:9.8(Critical)

A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Detection. The manipulation as part of POST/PUT/DELETE/...

CVSS:9.8(Critical)

linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.

CVSS:9.8(Critical)

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session,...

CVSS:9.8(Critical)

PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module

CVSS:9.8(Critical)

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code...