16,977 known vulnerabilities
Top Products
In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private director
In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This c
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user d
In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due t
In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a
In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the c
In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race conditi
In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag c
In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to a heap buffer overf
In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This could lead to local
In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset
An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.
Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perfo
OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memor
Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.
Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut witho
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to p
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attacke
Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physi
Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthori
Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without
Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of p
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local esc
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could le
In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local
In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalati
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escala
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escala
Microsoft Defender for Endpoint Spoofing Vulnerability
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege esc
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metada
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker co
Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a us
Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exp
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navi
Use after free in Data Transfer in Google Chrome on Chrome OS prior to 97.0.4692.99 allowed a remote attacker who convin
Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a us
Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit h
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started