Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

16,977 known vulnerabilities

981
CRITICAL
5,879
HIGH
5,898
MEDIUM
447
LOW

Top Products

android 8109 chrome 4748 tensorflow 431 chrome os 215 asylo 16 blink 12 mcp toolbox for databases 9 linux and chrome os 8 gvisor 7 fuchsia 6
13,206 CVEs · Page 148/265
4.0
CVE-2022-28784

Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arb

6.2
CVE-2022-28783

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninst

4.6
CVE-2022-28782

Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to

7.7
CVE-2022-28781

Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with

5.0
CVE-2022-28780

Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access locati

7.0
CVE-2022-20110

In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit

7.8
CVE-2022-20109

In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalatio

4.4
CVE-2022-20100

In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in

7.8
CVE-2022-20099

In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escala

4.4
CVE-2022-20098

In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in

4.7
CVE-2022-20097

In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information

4.4
CVE-2022-20096

In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information di

6.7
CVE-2022-20095

In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation

6.7
CVE-2022-20094

In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalat

7.8
CVE-2022-20093

In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could le

5.5
CVE-2022-20092

In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local informat

6.4
CVE-2022-20091

In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil

6.4
CVE-2022-20090

In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil

6.7
CVE-2022-20089

In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of pr

7.8
CVE-2022-20088

In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local esc

6.7
CVE-2022-20087

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2022-20085

In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local esc

7.8
CVE-2022-20084

In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This

5.3
CVE-2022-0882

A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capa

8.7
CVE-2021-22573

The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sur

5.3
CVE-2021-22556

The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache i

7.7
CVE-2022-25647

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl

6.7
CVE-2021-39814

In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could l

7.8
CVE-2021-39812

In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of pr

7.5
CVE-2021-39809

In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. T

7.8
CVE-2021-39808

In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground

7.8
CVE-2021-39807

In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a

6.5
CVE-2021-39805

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This coul

6.5
CVE-2021-39804

In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persi

6.5
CVE-2021-39803

In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remot

7.8
CVE-2021-39802

In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass.

7.8
CVE-2021-39801

In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escala

5.5
CVE-2021-39800

In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead t

7.8
CVE-2021-39799

In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation.

7.8
CVE-2021-39798

In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. Th

7.8
CVE-2021-39797

In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the co

7.3
CVE-2021-39796

In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmf

7.8
CVE-2021-39794

In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless deb

7.8
CVE-2021-0707

In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local

7.8
CVE-2021-0694

In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regai

4.4
CVE-2022-27837

A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Androi

8.4
CVE-2022-27836

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr

7.6
CVE-2022-27835

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

2.9
CVE-2022-27834

Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows a

4.4
CVE-2022-27833

Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.

Frequently Asked Questions

How many CVEs affect Google?

Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started