16,977 known vulnerabilities
Top Products
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a remote attacker to per
Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correct
PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allo
A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.
The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98
Stack-based buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Tab
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte
Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OT
Integer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before O
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Go
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain
The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to
Android allows users to cause a denial of service.
The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.
Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to
Google Chrome caches TLS sessions before certificate validation occurs.
SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).
mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vuln
mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulner
Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privil
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a sh
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 whe
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScri
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal scri
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the sound class.
A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.
An elevation of privilege vulnerability in the DTS sound driver could enable a local malicious application to execute ar
An elevation of privilege vulnerability in the MediaTek camera driver could enable a local malicious application to exec
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to exe
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to
An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access d
An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of
An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access
An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access da
An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access
An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code wi
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted fi
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted fi
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted fi
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted fi
A remote denial of service vulnerability in libskia could enable an attacker to use a specially crafted file to cause a
An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access
An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application to execute arbitrar
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary c
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started