CVE-2025-69172: WordPress Resurs theme <= 1.3 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in Resurs <= 1.3 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Browse CVE records published in June 2025, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 3542 matching CVEs · Page 6 of 71.
Unauthenticated Local File Inclusion in Resurs <= 1.3 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Unauthenticated Local File Inclusion in Orpheus <= 1.3 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Unauthenticated Local File Inclusion in Quirky <= 1.23 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
Published Jun 15, 2026 · Updated Jun 16, 2026
An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.
Published Jun 16, 2026 · Updated Jun 16, 2026
A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.
Published Jun 16, 2026 · Updated Jun 16, 2026
Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 versions.
Published Jun 15, 2026 · Updated Jun 16, 2026
An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
Published Jun 16, 2026 · Updated Jun 16, 2026
A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management and other administrative actions.
Published Jun 16, 2026 · Updated Jun 16, 2026
Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
Published Jun 15, 2026 · Updated Jun 16, 2026
Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.
Published Jun 15, 2026 · Updated Jun 16, 2026
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files appear in the application's trusted Received interface. These conditions establish a vector for arbitrary code execution if the payload is an APK file, or a denial-of-service condition through resource exhaustion from oversized transfers.
Published Jun 15, 2026 · Updated Jun 16, 2026
Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privileges.
Published Jun 16, 2026 · Updated Jun 16, 2026
Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.
Published Jun 16, 2026 · Updated Jun 16, 2026
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
Published Jun 16, 2026 · Updated Jun 16, 2026
Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.
Published Jun 15, 2026 · Updated Jun 15, 2026
A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Published Jun 15, 2026 · Updated Jun 15, 2026
Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.
Published Jun 15, 2026 · Updated Jun 15, 2026
A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Published Jun 9, 2026 · Updated Jun 15, 2026
A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a NULL pointer of type 'struct dhcp_opt' when an unexpected/invalid option token or parsing state causes the lookup to yield NULL. The instrumented fuzzing build reports 'runtime error: member access within null pointer of type struct dhcp_opt' and aborts.
Published Jun 15, 2026 · Updated Jun 15, 2026
Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25020100. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Published Jun 12, 2026 · Updated Jun 15, 2026
Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.98.
Published Jun 12, 2026 · Updated Jun 15, 2026
Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.76.
Published Jun 12, 2026 · Updated Jun 15, 2026
Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.104.
Published Jun 12, 2026 · Updated Jun 15, 2026
A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Published Jun 9, 2026 · Updated Jun 13, 2026
A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Published Jun 9, 2026 · Updated Jun 13, 2026
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Published Jun 9, 2026 · Updated Jun 13, 2026
A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data.
Published Jun 9, 2026 · Updated Jun 13, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.
Published Jun 11, 2026 · Updated Jun 12, 2026
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Published Jun 11, 2026 · Updated Jun 12, 2026
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
Published Jun 11, 2026 · Updated Jun 12, 2026
QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
Published Jun 10, 2026 · Updated Jun 12, 2026
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes, potentially turning it into a normal page table used in another process in which unrelated VMAs can afterwards be installed. If this happens in the middle of a concurrent gup_fast(), gup_fast() could end up walking the page tables of another process. While I don't see any way in which that immediately leads to kernel memory corruption, it is really weird and unexpected. Fix it with an explicit broadcast IPI through tlb_remove_table_sync_one(), just like we do in khugepaged when removing page tables for a THP collapse.
Published Jun 28, 2025 · Updated Jun 11, 2026
In the Linux kernel, the following vulnerability has been resolved: espintcp: fix skb leaks A few error paths are missing a kfree_skb.
Published Jun 18, 2025 · Updated Jun 11, 2026
Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.
Published Jun 11, 2026 · Updated Jun 11, 2026
During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.
Published Jun 10, 2026 · Updated Jun 11, 2026
During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM).
Published Jun 10, 2026 · Updated Jun 11, 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later
Published Jun 10, 2026 · Updated Jun 11, 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later
Published Jun 10, 2026 · Updated Jun 11, 2026