16,977 known vulnerabilities
Top Products
In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input va
In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing
In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could
In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informatio
In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. Th
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a m
In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This co
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call withou
In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead
In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to improper input validation
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lea
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's
In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic err
There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn cont
android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.
In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. Th
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0
Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to lau
Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certai
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keygu
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to cal
Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker
Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to acces
Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows l
Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access i
Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the serv
Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wif
Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid v
Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to acce
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to int
Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to access arbitrary file.
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferre
Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to acce
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access icc
Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbit
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some
Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FIN
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certa
Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password conf
Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch ce
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022
In audio DSP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In audio DSP, there is a possible memory corruption due to improper casting. This could lead to local escalation of priv
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalati
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalati
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started