16,977 known vulnerabilities
Top Products
In ComposeActivityEmailExternal of ComposeActivityEmailExternal.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a
In execTransact of Binder.java in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible local execution of arbitrar
In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corrupt
In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds c
In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot
The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, vid
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indo
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ In
An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indo
An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4
An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indo
In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission chec
In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation. This c
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. Thi
In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overf
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a heap buffer overflow. Th
It is possible to overlay the VPN dialog by a malicious application. This could lead to local escalation of privilege wi
An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation o
In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This cou
In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to a missing bounds
In ACELP_4t64_fx of c4t64fx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to
In AudioInputDescriptor::setClientActive of AudioInputDescriptor.cpp, there is possible memory corruption due to a use a
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer.
In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead
In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the
In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could le
In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insec
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and do
NVIDIA Shield TV Experience prior to v8.0, contains a vulnerability in the custom NVIDIA API used in the mount system se
On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create p
Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configur
NVIDIA Shield TV Experience prior to v8.0, contains a vulnerability in the NVIDIA Games App where it improperly exports
NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token i
Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is a
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwo
In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This
In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead t
In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permis
In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could le
In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset prote
In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local
In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remo
In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect boun
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This cou
In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This
In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. T
Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started