16,977 known vulnerabilities
Top Products
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4
An information disclosure vulnerability in the Android framework (file system). Product: Android. Versions: 7.0, 7.1.1,
An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.
An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0,
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su
Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to execute arbitrary code
The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.
Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arb
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data
In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to ga
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to an off-by-one error in a camera d
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, vari
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and r
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to alr
In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store a
In all Qualcomm products with Android releases from CAF using the Linux kernel, while reading audio data from an unspeci
In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function msm_dba_register_client,
In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp_check_stream_cfg_cm
In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and
In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing t
In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is accessed in one thre
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can r
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not che
In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function,
In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_
In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffe
In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_sh
Integer overflow in IAudioPolicyService.cpp in Android allows local users to gain privileges via a crafted application,
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
A elevation of privilege vulnerability in the MediaTek mmc driver. Product: Android. Versions: Android kernel. Android I
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android ke
A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A
A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Androi
A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android kernel. Android ID: A-3
A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID:
A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android ke
A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: Android kernel. Androi
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android ke
A elevation of privilege vulnerability in the Upstream kernel scsi driver. Product: Android. Versions: Android kernel. A
A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android
A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started