16,977 known vulnerabilities
Top Products
In ActivityThread.java, there is a possible way to collide the content provider's authorities. This could lead to local
In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to uncle
In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible wa
In alac decoder, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esca
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier d
In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to loc
In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth devi
The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side re
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable t
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the addre
A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC i
An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write
An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary
An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attack
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSI
An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive inf
An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthori
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain act
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitra
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execu
A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before vers
A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)
Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cro
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform
Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corrup
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote
Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject
Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exp
Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign
In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local i
In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of p
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privile
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privile
In apusys, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privile
In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information
In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information
In ccu, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege
In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information
In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In apusys, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escala
In edma driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of pr
In mdlactl driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local esca
In mdlactl driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of
In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa
In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local informatio
In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started