NA - CVE-2025-53676 - Jenkins Xooa Plugin 0.0.7 and earlier stores...
Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the...
NA - CVE-2025-53677 - Jenkins Xooa Plugin 0.0.7 and earlier does not...
Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.
NA - CVE-2025-53678 - Jenkins User1st uTester Plugin 1.1 and earlier...
Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to...
NA - CVE-2025-53742 - Jenkins Applitools Eyes Plugin 1.16.5 and...
Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read...
NA - CVE-2025-53743 - Jenkins Applitools Eyes Plugin 1.16.5 and...
Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
NA - CVE-2025-7381 - ImpactThis is an information disclosure...
ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could...
NA - CVE-2025-44525 - Texas Instruments CC2652RB LaunchPad SimpleLink...
Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data...
NA - CVE-2025-53645 - Zimbra Collaboration Suite (ZCS) before 9.0.0...
Zimbra Collaboration Suite (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive,...
NA - CVE-2025-0139 - An incorrect privilege assignment vulnerability...
An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate their...