16,977 known vulnerabilities
Top Products
In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege
In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege
In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can u
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap
Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had c
Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised
Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to poten
Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially
Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sa
Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had comprom
Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to per
The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due t
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input
In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app
In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings
In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead
In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent.
In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to rem
In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default
In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that
In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure defaul
In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This coul
In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bo
In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan resul
In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored bind
In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead
In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow.
In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a t
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local es
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local es
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap
Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the conte
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the r
Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap co
Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to i
Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to i
Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perfo
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b
Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of b
Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypas
Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sand
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain pote
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker t
Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak
Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof secu
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started