Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

16,977 known vulnerabilities

981
CRITICAL
5,879
HIGH
5,898
MEDIUM
447
LOW

Top Products

android 8109 chrome 4748 tensorflow 431 chrome os 215 asylo 16 blink 12 mcp toolbox for databases 9 linux and chrome os 8 gvisor 7 fuchsia 6
13,206 CVEs · Page 133/265
6.8
CVE-2022-3048

Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a loca

6.5
CVE-2022-3047

Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convin

8.8
CVE-2022-3046

Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to instal

8.8
CVE-2022-3045

Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to po

6.5
CVE-2022-3044

Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had

8.8
CVE-2022-3043

Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker wh

8.8
CVE-2022-3042

Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially

8.8
CVE-2022-3041

Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap c

8.8
CVE-2022-3040

Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap c

8.8
CVE-2022-3039

Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap c

8.8
CVE-2022-3038 KEV

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially explo

8.8
CVE-2022-2998

Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced

6.5
CVE-2022-2861

Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convince

6.5
CVE-2022-2860

Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass

8.8
CVE-2022-2859

Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a use

8.8
CVE-2022-2858

Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit

8.8
CVE-2022-2857

Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap c

6.5
CVE-2022-2856 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remo

8.8
CVE-2022-2855

Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap c

8.8
CVE-2022-2854

Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit

8.8
CVE-2022-2853

Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had

8.8
CVE-2022-2852

Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap c

7.5
CVE-2022-1941

A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3

5.9
CVE-2022-36027

TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel we

5.9
CVE-2022-36017

TensorFlow is an open source platform for machine learning. If `Requantize` is given `input_min`, `input_max`, `requeste

5.9
CVE-2022-36016

TensorFlow is an open source platform for machine learning. When `tensorflow::full_type::SubstituteFromAttrs` receives a

5.9
CVE-2022-36015

TensorFlow is an open source platform for machine learning. When `RangeSize` receives values that do not fit into an `in

5.9
CVE-2022-36014

TensorFlow is an open source platform for machine learning. When `mlir::tfg::TFOp::nameAttr` receives null type list att

5.9
CVE-2022-36013

TensorFlow is an open source platform for machine learning. When `mlir::tfg::GraphDefImporter::ConvertNodeDef` tries to

5.9
CVE-2022-36012

TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is giv

5.9
CVE-2022-36011

TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is giv

5.9
CVE-2022-36005

TensorFlow is an open source platform for machine learning. When `tf.quantization.fake_quant_with_min_max_vars_gradient`

5.9
CVE-2022-36004

TensorFlow is an open source platform for machine learning. When `tf.random.gamma` receives large input shape and rates,

5.9
CVE-2022-36003

TensorFlow is an open source platform for machine learning. When `RandomPoissonV2` receives large input shape and rates,

5.9
CVE-2022-36002

TensorFlow is an open source platform for machine learning. When `Unbatch` receives a nonscalar input `id`, it gives a `

5.9
CVE-2022-36001

TensorFlow is an open source platform for machine learning. When `DrawBoundingBoxes` receives an input `boxes` that is n

5.9
CVE-2022-36000

TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is giv

5.9
CVE-2022-35999

TensorFlow is an open source platform for machine learning. When `Conv2DBackpropInput` receives empty `out_backprop` inp

5.9
CVE-2022-35998

TensorFlow is an open source platform for machine learning. If `EmptyTensorList` receives an input `element_shape` with

5.9
CVE-2022-35997

TensorFlow is an open source platform for machine learning. If `tf.sparse.cross` receives an input `separator` that is n

5.9
CVE-2022-35996

TensorFlow is an open source platform for machine learning. If `Conv2D` is given empty `input` and the `filter` and `pad

5.9
CVE-2022-35995

TensorFlow is an open source platform for machine learning. When `AudioSummaryV2` receives an input `sample_rate` with m

5.9
CVE-2022-35994

TensorFlow is an open source platform for machine learning. When `CollectiveGather` receives an scalar input `input`, it

5.9
CVE-2022-35993

TensorFlow is an open source platform for machine learning. When `SetSize` receives an input `set_shape` that is not a 1

5.9
CVE-2022-35992

TensorFlow is an open source platform for machine learning. When `TensorListFromTensor` receives an `element_shape` of a

5.9
CVE-2022-35991

TensorFlow is an open source platform for machine learning. When `TensorListScatter` and `TensorListScatterV2` receive a

5.9
CVE-2022-36026

TensorFlow is an open source platform for machine learning. If `QuantizeAndDequantizeV3` is given a nonscalar `num_bits`

5.9
CVE-2022-36019

TensorFlow is an open source platform for machine learning. If `FakeQuantWithMinMaxVarsPerChannel` is given `min` or `ma

5.9
CVE-2022-36018

TensorFlow is an open source platform for machine learning. If `RaggedTensorToVariant` is given a `rt_nested_splits` lis

5.9
CVE-2022-35990

TensorFlow is an open source platform for machine learning. When `tf.quantization.fake_quant_with_min_max_vars_per_chann

Frequently Asked Questions

How many CVEs affect Google?

Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started