16,977 known vulnerabilities
Top Products
Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially expl
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a rem
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap co
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap co
Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit hea
Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gai
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions bef
Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation cou
Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could le
The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phone
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploita
Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation cou
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could
Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could le
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that lead
A pointer in an ADSPRPC command is not properly validated in all Android releases from CAF using the Linux kernel (Andro
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condit
While parsing over-the-air information elements in all Android releases from CAF using the Linux kernel (Android for MSM
While processing a debug log event from firmware in all Android releases from CAF using the Linux kernel (Android for MS
While processing a WMI_APFIND event in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS
In __wlan_hdd_cfg80211_vendor_scan() in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox O
Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM,
In the audio debugfs in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD A
While padding or shrinking a nested wmi packet in all Android releases from CAF using the Linux kernel (Android for MSM,
A race condition exists in a driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS
In a firmware memory dump feature in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS f
An integer overflow to buffer overflow vulnerability exists in the ADSPRPC heap manager in all Android releases(Android
In the cpuidle driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that lead
Lack of copy_from_user and information leak in function "msm_ois_subdev_do_ioctl, file msm_ois.c can lead to a camera cr
In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security p
Integer overflow can occur in msm_pcm_adsp_stream_cmd_put() function if the user supplied data "param_length" goes beyon
While reading the data from buffer in dci_process_ctrl_status() there can be buffer over-read problem if the len is not
In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security p
Buffer over-read may happen in wma_process_utf_event() due to improper buffer length validation before writing into para
While processing a message from firmware in htt_t2h_msg_handler_fast() in Android releases from CAF using the linux kern
If the fdt_totalsize is reported as 0 for the current device tree, it bypasses an error check for a valid device tree in
While processing a compressed kernel image, a buffer overflow can occur in Android releases from CAF using the linux ker
While processing the system path, an out of bounds access can occur in Android releases from CAF using the linux kernel
While processing the USB StrSerialDescriptor array, an array index out of bounds can occur in Android releases from CAF
In wma_nan_rsp_event_handler() in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM,
If the seq_len is greater then CSR_MAX_RSC_LEN, a buffer overflow in __wlan_hdd_cfg80211_add_key() may occur when copyin
In __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur in Android releases from CAF using the li
Due to a race condition in a camera driver ioctl handler in Android releases from CAF using the linux kernel (Android fo
In the KGSL driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started