16,977 known vulnerabilities
Top Products
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker wi
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati
In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if
In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri
In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform U
Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced
Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convin
Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convin
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attack
Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform
Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker
Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploi
Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file a
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap co
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memo
Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit hea
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corru
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corru
In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This co
In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to lo
there is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with
In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the
In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This
In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-of-bounds read due to
In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This co
Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an
Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local atta
Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convi
Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker w
Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain
Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out
Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform ou
Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker
Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a
Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out of bounds memo
In da, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosur
In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio
In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no
Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started