16,977 known vulnerabilities
Top Products
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arb
Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninst
Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to
Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access locati
In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit
In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalatio
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in
In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escala
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in
In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information
In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information di
In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalat
In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could le
In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local informat
In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil
In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil
In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of pr
In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local esc
In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local esc
In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capa
The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sur
The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache i
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl
In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could l
In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of pr
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. T
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This coul
In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persi
In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remot
In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass.
In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escala
In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead t
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation.
In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. Th
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the co
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmf
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless deb
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local
In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regai
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Androi
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr
Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.
Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows a
Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started