Vulnerabilities in google

7,001 results
Vexday analysis

Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.

CVE-2026-7948HIGHRace in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicioEPSS 0.2%CVE-2026-11092HIGHInsufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2026-11692HIGHUse after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process EPSS 0.2%CVE-2026-0155MEDIUMIn ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information discEPSS 0.2%CVE-2026-11679HIGHUse after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2026-17774HIGHInsufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged networkEPSS 0.2%CVE-2023-6339CRITICALGoogle Nest WiFi Pro root code-execution & user-data compromiseEPSS 0.2%CVE-2026-0140MEDIUMIn RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosEPSS 0.2%CVE-2023-21284—In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper inEPSS 0.2%CVE-2024-47040CRITICALUse After Free in the android.hardware.radio.sap.ISap/slot2 serviceEPSS 0.2%CVE-2026-11701MEDIUMInappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2024-54317MEDIUMWordPress Web Stories plugin <= 1.37.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-1260HIGHInvalid Memory Access in Sentencepiece,EPSS 0.2%CVE-2023-21288—In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead EPSS 0.2%CVE-2026-102329MEDIUMCross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privilegeEPSS 0.2%CVE-2025-12729MEDIUMInappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user tEPSS 0.2%CVE-2026-0129MEDIUMIn RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure withEPSS 0.2%CVE-2024-32893HIGHIn _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local informatEPSS 0.2%CVE-2025-24959LOWEnvironment Variable Injection for dotenv API in zxEPSS 0.2%CVE-2026-11234MEDIUMInappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendeEPSS 0.2%