Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.25% | — | Jenkins Gradle PluginAIGradleAIJetbrains DevelocityAI | 16/9/2026 | 18/9/2026 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the… | |
| Pendiente de análisis | Baja (1.6) | 0.13% | — | Vaadin Flow Maven PluginAIVaadin Flow Gradle PluginAIVaadin Flow Plugin BaseAI | 19/5/2026 | 14/9/2026 | A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any… | |
| Analizada | Alta (8.3) | 0.80% | — | Gradle-completion | 29/1/2026 | 17/6/2026 | gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and including 9.3.0 that allows arbitrary code execution when a user triggers Bash tab completion in a project containing a malicious Gradle build file. The `gradle-completion`… | |
| Analizada | Alta (8.6) | 0.15% | — | Gradle | 16/1/2026 | 17/6/2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would… | |
| Analizada | Alta (8.6) | 0.17% | — | Gradle | 16/1/2026 | 17/6/2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would… | |
| Aplazada | Alta (8.8) | 0.24% | — | GradleAINet.rubygrapefruit Native-platformAI | 25/2/2025 | 17/6/2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library initialization could be vulnerable to a local… | |
| Aplazada | Alta (7.1) | 0.34% | — | Gradle DevelocityAI | 26/1/2025 | 17/6/2026 | Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in affected vulnerable versions) does not include the projects… | |
| Aplazada | Alta (8.3) | 0.47% | — | Gradle DevelocityAI | 26/1/2025 | 17/6/2026 | Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and provides some protection against brute-force… | |
| Modificada | Crítica (9.8) | 0.77% | — | Gradle Enterprise | 9/1/2024 | 17/6/2026 | In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an attacker logs in before the legitimate… | |
| Analizada | Media (5.3) | 0.67% | — | Gradle | 6/10/2023 | 17/6/2026 | Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote… | |
| Modificada | Media (6.5) | 0.21% | — | Gradle | 5/10/2023 | 17/6/2026 | Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permissions of the linked file to the resulting file. This leads to files having too much… | |
| Modificada | Media (6.5) | 0.77% | — | Jenkins Gradle | 26/7/2023 | 17/6/2026 | Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) in the build log in some circumstances. | |
| Analizada | Alta (8.1) | 0.53% | — | Gradle | 30/6/2023 | 17/6/2026 | Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives, Gradle did not check that files could be written outside of the unpack location. This could lead to important files being overwritten anywhere the Gradle process has… | |
| Modificada | Media (5.5) | 0.28% | — | Gradle | 30/6/2023 | 17/6/2026 | Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle can be made to write files into an… | |
| Modificada | Media (6.5) | 0.29% | — | Gradle Build Action | 28/4/2023 | 17/6/2026 | Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration cache enabled, potentially exposing secrets configured for the… | |
| Modificada | Crítica (9.8) | 0.99% | — | Gradle | 2/3/2023 | 17/6/2026 | Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) for PGP keys. Users of dependency verification in Gradle are vulnerable if they use long IDs for PGP keys in a `trusted-key` or `pgp` element in their dependency… | |
| Modificada | Media (6.3) | 3.1% | — | Snyk CLISnyk Cocoapods CLISnyk Docker CLISnyk Gradle CLI+4 | 30/11/2022 | 17/6/2026 | The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the… | |
| Modificada | Alta (7.5) | 0.81% | — | Gradle Enterprise | 21/10/2022 | 17/6/2026 | A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3. | |
| Modificada | Alta (7.5) | 0.76% | — | Gradle Enterprise | 7/10/2022 | 17/6/2026 | An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact address, via HTTP access to an accidentally exposed internal endpoint. This is fixed… | |
| Modificada | Media (4.4) | 0.56% | — | Gradle | 14/7/2022 | 17/6/2026 | Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through 7.4.2, there are some cases in which Gradle may skip that verification and… | |
| Modificada | Alta (7.5) | 0.92% | — | Gradle Enterprise | 6/6/2022 | 17/6/2026 | Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure. | |
| Modificada | Alta (7.2) | 1.3% | — | Gradle | 6/6/2022 | 17/6/2026 | Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution. | |
| Modificada | Crítica (9.8) | 1.8% | — | Gradle Enterprise | 25/3/2022 | 17/6/2026 | Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API. | |
| Modificada | Alta (8.1) | 1.0% | — | Gradle Enterprise | 17/3/2022 | 17/6/2026 | In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute malicious code as part of a build. As of… | |
| Modificada | Media (6.5) | 0.54% | — | Gradle Enterprise | 16/3/2022 | 17/6/2026 | Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During the sign-in process, Keycloak sets browser cookies that effectively provide remember-me functionality. For backwards compatibility with older Safari versions, Keycloak… |