ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-45157
+1 in the same advisory: …45156
Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • splashin splashin
CVE-2018-6195
+1 in the same advisory: …6194
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator,

admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.

NVD description · AI analysis pending
7.2
group max
4% PoC ×2
  • splashing images project splashing images