16,977 known vulnerabilities
Top Products
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcas
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLSer
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer v
An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Pro
In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This co
In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could
Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to en
Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a u
Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a
Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install
Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a u
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who c
Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacke
Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to ins
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cro
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit
Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a u
Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who
Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attac
Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to
Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convin
Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convi
Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced
Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a
Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap
Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit
Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap
Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote att
In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code executi
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could le
In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could
In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing
In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration.
In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input v
In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to
In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a miss
In Bluetooth, there are possible process crashes due to dereferencing a null pointer. This could lead to remote denial o
In Bluetooth, there is a possible crash due to a missing null check. This could lead to remote denial of service with no
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to s
In the Framework, there is a possible way to enable a work profile without user consent due to a tapjacking/overlay atta
In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing
In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead t
In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. T
In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission che
In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to lo
In Media, there is a possible code execution due to a use after free. This could lead to local escalation of privilege w
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started