16,977 known vulnerabilities
Top Products
Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap
Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit hea
Use after free in Navigation in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit he
Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker
Use after free in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corru
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitra
Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who con
Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corru
Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap cor
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri
In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local informati
In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote d
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN,
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate
Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit hea
In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections
In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an
In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead
In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a
In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Cod
In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permis
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation
In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. Thi
In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. Th
In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could l
In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninit
In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. Th
In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. Thi
In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input val
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially expl
Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap c
In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remot
In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflo
In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the cod
In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mit
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification ac
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started