Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

16,977 known vulnerabilities

981
CRITICAL
5,879
HIGH
5,898
MEDIUM
447
LOW

Top Products

android 8109 chrome 4748 tensorflow 431 chrome os 215 asylo 16 blink 12 mcp toolbox for databases 9 linux and chrome os 8 gvisor 7 fuchsia 6
13,206 CVEs · Page 94/265
4.4
CVE-2023-21314

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information

7.8
CVE-2023-21313

In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could l

5.5
CVE-2023-21312

In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could lead to local informat

5.5
CVE-2023-21311

In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass.

6.7
CVE-2023-21310

In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation

5.5
CVE-2023-21309

In libcore, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d

5.5
CVE-2023-21308

In Composer, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation o

5.0
CVE-2023-21307

In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android devi

5.5
CVE-2023-21306

In ContentService, there is a possible way to read installed sync content providers due to side channel information disc

5.5
CVE-2023-21305

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side cha

5.5
CVE-2023-21304

In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to

5.5
CVE-2023-21303

In Content, here is a possible way to determine whether an app is installed, without query permissions, due to side chan

5.5
CVE-2023-21302

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to

5.5
CVE-2023-21301

In ActivityManagerService, there is a possible way to determine whether an app is installed, without query permissions,

5.5
CVE-2023-21300

In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to s

5.5
CVE-2023-21299

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to

7.8
CVE-2023-21298

In Slice, there is a possible disclosure of installed applications due to side channel information disclosure. This coul

4.4
CVE-2023-21297

In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to l

5.5
CVE-2023-21296

In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side

5.5
CVE-2023-21295

In SliceManagerService, there is a possible way to check if a content provider is installed due to a missing null check.

5.5
CVE-2023-21294

In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to loc

5.5
CVE-2023-21293

In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, du

5.5
CVE-2022-20264

In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due

7.8
CVE-2021-39810

In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactl

7.8
CVE-2023-40140

In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code du

5.5
CVE-2023-40139

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lea

3.3
CVE-2023-40138

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lea

3.3
CVE-2023-40137

In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused depu

3.3
CVE-2023-40136

In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This

3.3
CVE-2023-40135

In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy

3.3
CVE-2023-40134

In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This cou

5.5
CVE-2023-40133

In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused depu

7.0
CVE-2023-40131

In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local es

7.8
CVE-2023-40130

In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. Th

8.8
CVE-2023-40129

In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could

7.8
CVE-2023-40128

In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could l

3.3
CVE-2023-40127

In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local

7.8
CVE-2023-40125

In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. Th

5.5
CVE-2023-40123

In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused

5.5
CVE-2023-40121

In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This c

7.8
CVE-2023-40120

In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input

7.8
CVE-2023-40117

In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This

7.8
CVE-2023-40116

In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions du

8.8
CVE-2023-5472

Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit hea

7.5
CVE-2023-35663

In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This coul

7.5
CVE-2023-35656

In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds c

6.5
CVE-2023-5487

Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a u

4.3
CVE-2023-5486

Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof securit

4.3
CVE-2023-5485

Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass aut

6.5
CVE-2023-5484

Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof se

Frequently Asked Questions

How many CVEs affect Google?

Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started