16,977 known vulnerabilities
Top Products
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the rendere
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compro
Type confusion in Blink in Google Chrome prior to 81.0.4044.138 allowed a remote attacker to potentially exploit heap co
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap co
Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised
Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the rend
Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perf
Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap
Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially
Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially per
Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation
In crus_afe_callback of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. Th
In psi_write of psi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local e
In simulatePackageSuspendBroadcast of NotificationManagerService.java, there is a missing permission check. This could l
In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version che
In onKeyguardVisibilityChanged of key_store_service.cpp, there is a missing permission check. This could lead to local e
In onShowingStateChanged of KeyguardStateMonitor.java, there is a possible inappropriate read due to a logic error. This
In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This coul
In GattServer::SendResponse of gatt_server.cc, there is a possible out of bounds write due to an incorrect bounds check.
In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could
In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to l
In navigateUpToLocked of ActivityStack.java, there is a possible permission bypass due to a confused deputy. This could
In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for s
In startActivities of ActivityStartController.java, there is a possible escalation of privilege due to a confused deputy
In setImageHeight and setImageWidth of ExifUtils.cpp, there is a possible out of bounds write due to an incorrect bounds
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This
In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification cont
In mnld, an incorrect configuration in driver_cfg of mnld for meta factory mode.Product: AndroidVersions: Android SoCAnd
An improper authorization in the receiver component of Email.Product: AndroidVersions: Android SoCAndroid ID: A-14981304
An improper authorization in the receiver component of the Android Suite Daemon.Product: AndroidVersions: Android SoCAnd
An improper authorization while processing the provisioning data.Product: AndroidVersions: Android SoCAndroid ID: A-1498
In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions byp
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A crafted application ca
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determi
An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software. The Quram image codec libra
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass Factory Reset Protection (
An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The S.LSI Wi-Fi drivers have a
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protectio
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 chipsets) software. Th
An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) (Exynos chipsets) software. Attackers
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protectio
Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (P
There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q
A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 all
TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the co
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in
OpenThread before 2019-12-13 has a stack-based buffer overflow in MeshCoP::Commissioner::GeneratePskc.
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentia
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started