Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gradle Completion HIGH 7.8
CVE-2026-25063

gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and inc…

Fix: after 9.3.0
Fix from $1,950 2026-01-29
Gradle HIGH 7.4
CVE-2026-22816

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…

Fix: 8.14.4 / 9.3.0+
Fix from $1,950 2026-01-16
Gradle HIGH 7.4
CVE-2026-22865

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…

Fix: 8.14.4 / 9.3.0+
Fix from $1,950 2026-01-16
Enterprise CRITICAL 9.8
CVE-2023-49238

In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of…

Fix: 2023.1+
Fix from $2,300 2024-01-09
Gradle MEDIUM 5.3
CVE-2023-42445

Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, reso…

Fix: 7.6.3 / 8.4.0+
Fix from $1,600 2023-10-06
Gradle MEDIUM 6.5
CVE-2023-44387

Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle…

Fix: 7.6.3 / 8.4.0+
Fix from $1,600 2023-10-05
Gradle HIGH 8.1
CVE-2023-35947

Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…

Fix: 7.6.2 / 8.2.0+
Fix from $1,950 2023-06-30
Gradle MEDIUM 5.5
CVE-2023-35946

Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependen…

Fix: 7.6.2 / 8.2.0+
Fix from $1,600 2023-06-30
Build Action MEDIUM 6.5
CVE-2023-30853

Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradl…

Fix: 2.4.2+
Fix from $1,600 2023-04-28
Gradle CRITICAL 9.8
CVE-2023-26053

Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) f…

Fix: 6.9.4 / 7.6.1+
Fix from $2,300 2023-03-02
Enterprise HIGH 7.5
CVE-2022-41575

A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a …

Fix: 2022.3.3+
Fix from $1,950 2022-10-21
Enterprise HIGH 7.5
CVE-2022-41574

An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emai…

Fix: 2022.3.2+
Fix from $1,950 2022-10-07
Gradle Enterprise HIGH 7.5
CVE-2022-30587

Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.

Fix: 2022.2.3+
Fix from $1,950 2022-06-06
Gradle HIGH 7.2
CVE-2022-30586

Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.

Fix: 1.3.1+
Fix from $1,950 2022-06-06
Enterprise CRITICAL 9.8
CVE-2022-27919

Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configura…

Fix: after 2021.4.3
Fix from $2,300 2022-03-25
Enterprise HIGH 8.1
CVE-2022-25364

In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed…

Fix: 2021.4.2+
Fix from $1,950 2022-03-17
Enterprise MEDIUM 6.5
CVE-2022-27225

Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During…

Fix: 2021.4.3+
Fix from $1,600 2022-03-16
Gradle HIGH 7.5
CVE-2022-23630

Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification …

Fix: after 7.3.3
Fix from $1,950 2022-02-10
Build Cache Node CRITICAL 9.8
CVE-2021-41589

In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when r…

Fix: 10.0 / 2021.3+
Fix from $2,300 2021-10-27
Enterprise HIGH 7.2
CVE-2021-41619

An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The…

Fix: 2021.1.2+
Fix from $1,950 2021-10-27
Enterprise MEDIUM 5.3
CVE-2021-41590

In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation config…

Fix: 2021.3+
Fix from $1,600 2021-10-27
Gradle HIGH 8.1
CVE-2021-41588

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…

Fix: 2021.1.3+
Fix from $1,950 2021-09-24
Gradle HIGH 7.5
CVE-2021-41586

In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.

Fix: 2021.1.3+
Fix from $1,950 2021-09-24
Gradle HIGH 7.5
CVE-2021-41587

In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.

Fix: 2021.1.3+
Fix from $1,950 2021-09-24
Gradle HIGH 7.5
CVE-2021-41584

Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration deta…

Fix: 2021.1.3+
Fix from $1,950 2021-09-24
Gradle HIGH 7.5
CVE-2021-32751

Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradl…

Fix: 7.2+
Fix from $1,950 2021-07-20
Gradle HIGH 7.8
CVE-2021-29428

In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to …

Fix: 7.0+
Fix from $1,950 2021-04-13
Gradle HIGH 7.2
CVE-2021-29427

In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repo…

Fix: 7.0+
Fix from $1,950 2021-04-13
Gradle MEDIUM 5.5
CVE-2021-29429

In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downl…

Fix: 7.0+
Fix from $1,600 2021-04-12
Enterprise Test Distribution Agent MEDIUM 6.5
CVE-2021-26719

A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1…

Fix: 1.3.2+
Fix from $1,600 2021-02-09