Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-25063
gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and inc…
Gradle Completion
after 9.3.0
HIGH 7.4
CVE-2026-22816
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…
Gradle
8.14.4 / 9.3.0+
HIGH 7.4
CVE-2026-22865
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…
Gradle
8.14.4 / 9.3.0+
CRITICAL 9.8
CVE-2023-49238
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of…
Enterprise
2023.1+
MEDIUM 5.3
CVE-2023-42445
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, reso…
Gradle
7.6.3 / 8.4.0+
MEDIUM 6.5
CVE-2023-44387
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle…
Gradle
7.6.3 / 8.4.0+
HIGH 8.1
CVE-2023-35947
Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…
Gradle
7.6.2 / 8.2.0+
MEDIUM 5.5
CVE-2023-35946
Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependen…
Gradle
7.6.2 / 8.2.0+
MEDIUM 6.5
CVE-2023-30853
Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradl…
Build Action
2.4.2+
CRITICAL 9.8
CVE-2023-26053
Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) f…
Gradle
6.9.4 / 7.6.1+
HIGH 7.5
CVE-2022-41575
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a …
Enterprise
2022.3.3+
HIGH 7.5
CVE-2022-41574
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emai…
Enterprise
2022.3.2+
HIGH 7.5
CVE-2022-30587
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
Gradle Enterprise
2022.2.3+
HIGH 7.2
CVE-2022-30586
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.
Gradle
1.3.1+
CRITICAL 9.8
CVE-2022-27919
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configura…
Enterprise
after 2021.4.3
HIGH 8.1
CVE-2022-25364
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed…
Enterprise
2021.4.2+
MEDIUM 6.5
CVE-2022-27225
Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During…
Enterprise
2021.4.3+
HIGH 7.5
CVE-2022-23630
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification …
Gradle
after 7.3.3
CRITICAL 9.8
CVE-2021-41589
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when r…
Build Cache Node
10.0 / 2021.3+
HIGH 7.2
CVE-2021-41619
An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The…
Enterprise
2021.1.2+
MEDIUM 5.3
CVE-2021-41590
In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation config…
Enterprise
2021.3+
HIGH 8.1
CVE-2021-41588
In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…
Gradle
2021.1.3+
HIGH 7.5
CVE-2021-41586
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.
Gradle
2021.1.3+
HIGH 7.5
CVE-2021-41587
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.
Gradle
2021.1.3+
HIGH 7.5
CVE-2021-41584
Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration deta…
Gradle
2021.1.3+
HIGH 7.5
CVE-2021-32751
Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradl…
Gradle
7.2+
HIGH 7.8
CVE-2021-29428
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to …
Gradle
7.0+
HIGH 7.2
CVE-2021-29427
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repo…
Gradle
7.0+
MEDIUM 5.5
CVE-2021-29429
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downl…
Gradle
7.0+
MEDIUM 6.5
CVE-2021-26719
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1…
Enterprise Test Distribution Agent
1.3.2+