Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-45157 +1 in the same advisory: …45156 | Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users. Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2018-6195 +1 in the same advisory: …6194 | admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php. NVD description · AI analysis pending | 7.2 group max | 4% | PoC ×2 |
| — |