16,977 known vulnerabilities
Top Products
In ioctl_dpm_qos_update and ioctl_event_control_set of (TBD), there is a possible out of bounds write due to an integer
Product: AndroidVersions: Android kernelAndroid ID: A-209906686References: N/A
In auth_store of sjtag-driver.c, there is a possible read of uninitialized memory due to a missing bounds check. This co
Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A
In exynos_secEnv_init of mach-gs101.c, there is a possible out of bounds read due to an incorrect bounds check. This cou
Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A
In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This
Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-210594998References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A
In various methods of kernel base drivers, there is a possible out of bounds write due to a heap buffer overflow. This c
In asn1_parse of asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to loc
Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A
In asn1_p256_int of crypto/asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could l
Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A
In asn1_ec_pkey_parse of acropora/crypto/asn1_common.c, there is a possible out of bounds read due to an incorrect bound
In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This c
In ipu_core_jqs_msg_transport_kernel_write_sync of ipu-core-jqs-msg-transport.c, there is a possible use-after-free due
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local esca
In rcu_cblist_dequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to
In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
Product: AndroidVersions: Android kernelAndroid ID: A-210712565References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A
In TBD of TBD, there is a possible use-after-free due to a race condition. This could lead to local escalation of privil
In nfa_dm_check_set_config of nfa_dm_main.cc, there is a possible out of bounds write due to a missing bounds check. Thi
In uploadFile of FileUploadServiceImpl.java, there is a possible incorrect file access due to a confused deputy. This co
In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade
In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content provi
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion
In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parce
In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escal
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could le
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app t
In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead t
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi setti
In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could lead to local escala
In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due
In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permis
In lg_probe and related functions of hid-lg.c and other USB HID files, there is a possible out of bounds read due to imp
In nci_proc_rf_management_ntf of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow.
In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phon
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remo
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interacti
In GBoard, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local
In deletePackageX of DeletePackageHelper.java, there is a possible way for a Guest user to reset pre-loaded applications
In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check
In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started