Vulnerabilities

Summary — last 7 days

New vulnerabilities2,965▲ 27 vs. last week
Critical / high1,456▲ 193 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)272▼ 254 vs. last week
–

58 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (5.4)0.25%—Jenkins Gradle PluginAIGradleAIJetbrains DevelocityAI9/16/20269/18/2026
Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the…
Awaiting AnalysisLow (1.6)0.13%—Vaadin Flow Maven PluginAIVaadin Flow Gradle PluginAIVaadin Flow Plugin BaseAI5/19/20269/14/2026
A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any…
AnalyzedHigh (8.3)0.80%—Gradle-completion1/29/20266/17/2026
gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and including 9.3.0 that allows arbitrary code execution when a user triggers Bash tab completion in a project containing a malicious Gradle build file. The `gradle-completion`…
AnalyzedHigh (8.6)0.15%—Gradle1/16/20266/17/2026
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would…
AnalyzedHigh (8.6)0.17%—Gradle1/16/20266/17/2026
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would…
DeferredHigh (8.8)0.24%—GradleAINet.rubygrapefruit Native-platformAI2/25/20256/17/2026
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library initialization could be vulnerable to a local…
DeferredHigh (7.1)0.34%—Gradle DevelocityAI1/26/20256/17/2026
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in affected vulnerable versions) does not include the projects…
DeferredHigh (8.3)0.47%—Gradle DevelocityAI1/26/20256/17/2026
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and provides some protection against brute-force…
ModifiedCritical (9.8)0.77%—Gradle Enterprise1/9/20246/17/2026
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an attacker logs in before the legitimate…
AnalyzedMedium (5.3)0.67%—Gradle10/6/20236/17/2026
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote…
ModifiedMedium (6.5)0.21%—Gradle10/5/20236/17/2026
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permissions of the linked file to the resulting file. This leads to files having too much…
ModifiedMedium (6.5)0.77%—Jenkins Gradle7/26/20236/17/2026
Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) in the build log in some circumstances.
AnalyzedHigh (8.1)0.53%—Gradle6/30/20236/17/2026
Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives, Gradle did not check that files could be written outside of the unpack location. This could lead to important files being overwritten anywhere the Gradle process has…
ModifiedMedium (5.5)0.28%—Gradle6/30/20236/17/2026
Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle can be made to write files into an…
ModifiedMedium (6.5)0.29%—Gradle Build Action4/28/20236/17/2026
Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration cache enabled, potentially exposing secrets configured for the…
ModifiedCritical (9.8)0.99%—Gradle3/2/20236/17/2026
Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) for PGP keys. Users of dependency verification in Gradle are vulnerable if they use long IDs for PGP keys in a `trusted-key` or `pgp` element in their dependency…
ModifiedMedium (6.3)3.1%—Snyk CLISnyk Cocoapods CLISnyk Docker CLISnyk Gradle CLI+411/30/20226/17/2026
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the…
ModifiedHigh (7.5)0.81%—Gradle Enterprise10/21/20226/17/2026
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.
ModifiedHigh (7.5)0.76%—Gradle Enterprise10/7/20226/17/2026
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact address, via HTTP access to an accidentally exposed internal endpoint. This is fixed…
ModifiedMedium (4.4)0.56%—Gradle7/14/20226/17/2026
Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through 7.4.2, there are some cases in which Gradle may skip that verification and…
ModifiedHigh (7.5)0.92%—Gradle Enterprise6/6/20226/17/2026
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
ModifiedHigh (7.2)1.3%—Gradle6/6/20226/17/2026
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.
ModifiedCritical (9.8)1.8%—Gradle Enterprise3/25/20226/17/2026
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.
ModifiedHigh (8.1)1.0%—Gradle Enterprise3/17/20226/17/2026
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute malicious code as part of a build. As of…
ModifiedMedium (6.5)0.54%—Gradle Enterprise3/16/20226/17/2026
Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During the sign-in process, Keycloak sets browser cookies that effectively provide remember-me functionality. For backwards compatibility with older Safari versions, Keycloak…