Enterprise

Vendor:

First CVE: Apr 22, 2019 · Active for 7 years

23
Total CVEs
More Total CVEs than 96% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Enterprise over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2019
7 years ago
Most Recent CVE
Jan 26, 2025
547 days ago

CVE Severity & Scoring

Enterprise23 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local1 (4.3%)
Network21 (91.3%)
Unknown0 (0.0%)
Physical1 (4.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low3 (13.0%)
High2 (8.7%)
None18 (78.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous a
Mar 25, 20229.832NONO
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node wit
Oct 27, 20219.830NONO
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.
Apr 22, 20199.829NONO
In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.
Apr 22, 20199.829NONO
An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the abil
Sep 18, 20208.828NONO
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash
Jan 26, 20258.327NONO
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system us
Jan 9, 20249.826NONO
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g
Oct 21, 20227.525NONO
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content
Oct 7, 20227.525NONO
An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The installation configuration use
Oct 27, 20217.224NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Enterprise

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2018.515.50.3%00
2018.217.51.0%00