16,977 known vulnerabilities
Top Products
In BTA_DmPinReply of bta_dm_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could
In PromiseBuiltinsAssembler::NewPromiseCapability of builtins-promise.cc, there is a possible out of bounds read in v8 J
In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks.
In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This cou
In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free.
In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. Thi
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. Thi
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing b
In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to loc
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure w
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure defaul
In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additiona
In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input valid
In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device
In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead
In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Bl
WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers t
Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements wit
A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.
An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that sign
Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.
Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDoc
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with
In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible
An Integer Overflow exists in WebKit in Google Chrome before Blink M11 in the macOS WebCore::GraphicsContext::fillRect f
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a
An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windo
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow. This co
In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing bounds check. This could
In VlcDequantH263IntraBlock_SH of vlc_dequant.cpp, there is a possible out of bounds write due to a missing bounds check
In PV_DecodePredictedIntraDC of dec_pred_intra_dc.cpp, there is a possible out of bounds write due to a missing bounds c
In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching o
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permi
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installat
In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a miss
NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it
NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra bootloader contains a vulnerability where the software perform
On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowl
The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0
In Platform, there is a possible bypass of user interaction requirements due to background app interception. This could
In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial
In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remote escalation of priv
In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure
In the Package Manager service, there is a possible information disclosure due to a confused deputy. This could lead to
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started