Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

16,977 known vulnerabilities

981
CRITICAL
5,879
HIGH
5,898
MEDIUM
447
LOW

Top Products

android 8109 chrome 4748 tensorflow 431 chrome os 215 asylo 16 blink 12 mcp toolbox for databases 9 linux and chrome os 8 gvisor 7 fuchsia 6
13,206 CVEs · Page 93/265
5.5
CVE-2023-21366

In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/des

5.5
CVE-2023-21365

In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in th

5.5
CVE-2023-21364

In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent deni

5.5
CVE-2023-21362

In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with

8.8
CVE-2023-21361

In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalat

6.7
CVE-2023-21360

In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalat

4.4
CVE-2023-21359

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information

7.8
CVE-2023-21358

In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to

4.4
CVE-2023-21357

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

8.8
CVE-2023-21356

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal

7.8
CVE-2023-21355

In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation

5.5
CVE-2023-21354

In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions,

7.5
CVE-2023-21353

In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disc

5.5
CVE-2023-21352

In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

7.8
CVE-2023-21351

In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead

5.5
CVE-2023-21350

In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to

3.3
CVE-2023-21349

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to

3.3
CVE-2023-21348

In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to s

7.5
CVE-2023-21347

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio

3.3
CVE-2023-21346

In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissio

3.3
CVE-2023-21345

In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, du

5.5
CVE-2023-21344

In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to si

7.8
CVE-2023-21343

In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to lo

7.8
CVE-2023-21342

In RemoteSpeechRecognitionService of RemoteSpeechRecognitionService.java, there is a possible way to launch an activity

7.8
CVE-2023-21341

In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This co

5.5
CVE-2023-21340

In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local i

7.5
CVE-2023-21339

In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could

5.5
CVE-2023-21338

In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to sid

7.8
CVE-2023-21337

In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side

5.5
CVE-2023-21336

In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to sid

5.5
CVE-2023-21335

In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch

5.5
CVE-2023-21334

In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the c

5.5
CVE-2023-21333

In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to si

5.5
CVE-2023-21332

In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to si

5.5
CVE-2023-21331

In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side

5.5
CVE-2023-21330

In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to

5.5
CVE-2023-21329

In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check.

7.8
CVE-2023-21328

In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due t

5.5
CVE-2023-21327

In Permission Manager, there is a possible way to determine whether an app is installed, without query permissions, due

5.5
CVE-2023-21326

In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions,

5.5
CVE-2023-21325

In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch

7.8
CVE-2023-21324

In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due t

5.5
CVE-2023-21323

In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to

5.5
CVE-2023-21321

In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lea

5.5
CVE-2023-21320

In Device Policy, there is a possible way to verify if a particular admin app is registered on the device due to side ch

5.5
CVE-2023-21319

In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosur

5.5
CVE-2023-21318

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side cha

5.5
CVE-2023-21317

In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to s

5.5
CVE-2023-21316

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side cha

6.5
CVE-2023-21315

In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote (proximal/

Frequently Asked Questions

How many CVEs affect Google?

Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started