Google records
16,718 published records for vendor google.
Researcher profile
- Entered KEV
- 113 · 0.7%
- Weaponized
- 135 · 0.8%
- Pre-auth RCE
- 1,845
- With a fix record
- 41.9%
- Median publish → KEV
- 29 days
Recurring classes
- CWE-416 Use After Free1,994
- CWE-787 Out-of-bounds Write1,647
- CWE-20 Improper Input Validation1,348
- CWE-125 Out-of-bounds Read1,270
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer830
- CWE-862 Missing Authorization790
The weakness classes this vendor ships most often: where to look.
CWEAll records
10,000+ records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-0497Weaponized | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Critical9.8 | KEV | 99.9% | Feb 5, 2014 |
95Now | CVE-2023-4863Weaponized | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | High8.8 | KEV | 100.0% | Sep 12, 2023 |
95Now | CVE-2011-0611Weaponized | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | High8.8 | KEV | 99.4% | Apr 13, 2011 |
90Now | CVE-2018-17463Weaponized | Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sgoogle · chrome | High8.8 | KEV | 84.6% | Nov 14, 2018 |
90Now | CVE-2021-21224Weaponized | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craftgoogle · chrome · CWE-843 | High8.8 | KEV | 84.2% | Apr 26, 2021 |
89Now | CVE-2012-0754Weaponized | Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.xadobe · flash player · CWE-787 | High8.1 | KEV | 91.2% | Feb 16, 2012 |
89Now | CVE-2020-6418Weaponized | Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | High8.8 | KEV | 78.8% | Feb 27, 2020 |
88Now | CVE-2018-15982Weaponized | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.adobe · flash player · CWE-416 | High7.8 | KEV | 89.6% | Jan 18, 2019 |
88Now | CVE-2018-4878Weaponized | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.adobe · flash player · CWE-416 | High7.8 | KEV | 89.5% | Feb 6, 2018 |
86Now | CVE-2022-2294Weaponized | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption viagoogle · chrome · CWE-787 | High8.8 | KEV | 70.5% | Jul 27, 2022 |
86Now | CVE-2021-21220Weaponized | Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit hegoogle · chrome · CWE-787 | High8.8 | KEV | 70.4% | Apr 26, 2021 |
85Now | CVE-2015-8651Weaponized | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on adobe · air sdk · CWE-190 | High8.8 | KEV | 67.7% | Dec 28, 2015 |
84Now | CVE-2021-30551Weaponized | Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | High8.8 | KEV | 64.7% | Jun 15, 2021 |
84Now | CVE-2021-30632Weaponized | Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafgoogle · chrome · CWE-787 | High8.8 | KEV | 63.2% | Oct 8, 2021 |
83Now | CVE-2019-2215Weaponized | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.google · android · CWE-416 | High7.8 | KEV | 72.1% | Oct 11, 2019 |
83Now | CVE-2018-6065Weaponized | Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3google · chrome · CWE-190 | High8.8 | KEV | 60.3% | Nov 14, 2018 |
82Now | CVE-2026-2441Weaponized | Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a cragoogle · chrome · CWE-416 | High8.8 | KEV | 55.1% | Feb 13, 2026 |
81Now | CVE-2016-0984Weaponized | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2adobe · flash player · CWE-416 | High8.8 | KEV | 54.5% | Feb 10, 2016 |
81Now | CVE-2020-15999Weaponized | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vigoogle · chrome · CWE-787 | Critical9.6 | KEV | 44.3% | Nov 2, 2020 |
80Now | CVE-2011-0609Weaponized | Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier onadobe · flash player | High7.8 | KEV | 63.5% | Mar 15, 2011 |
80Now | CVE-2019-13720Weaponized | Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a cragoogle · chrome · CWE-416 | High8.8 | KEV | 49.1% | Nov 25, 2019 |
80Now | CVE-2023-5217Weaponized | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potengoogle · chrome · CWE-787 | High8.8 | KEV | 49.0% | Sep 28, 2023 |
80Now | CVE-2026-85046Weaponized | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crgoogle · chrome · CWE-843 | High8.8 | KEV | 48.9% | Sep 3, 2026 |
79This week | CVE-2020-16009Weaponized | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption google · chrome · CWE-787 | High8.8 | KEV | 48.3% | Nov 2, 2020 |
79This week | CVE-2016-1646Weaponized | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consgoogle · chrome · CWE-125 | High8.8 | KEV | 48.1% | Mar 29, 2016 |
- CVE-2014-049799Now
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerFeb 5, 2014
- CVE-2023-486395Now
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
HighCVSS 8.8KEVWeaponizedEPSS 100%google · chromeSep 12, 2023
- CVE-2011-061195Now
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
HighCVSS 8.8KEVWeaponizedEPSS 99%adobe · flash playerApr 13, 2011
- CVE-2018-1746390Now
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a s
HighCVSS 8.8KEVWeaponizedEPSS 85%google · chromeNov 14, 2018
- CVE-2021-2122490Now
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft
HighCVSS 8.8KEVWeaponizedEPSS 84%google · chromeApr 26, 2021
- CVE-2012-075489Now
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x
HighCVSS 8.1KEVWeaponizedEPSS 91%adobe · flash playerFeb 16, 2012
- CVE-2020-641889Now
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 79%google · chromeFeb 27, 2020
- CVE-2018-1598288Now
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.
HighCVSS 7.8KEVWeaponizedEPSS 90%adobe · flash playerJan 18, 2019
- CVE-2018-487888Now
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.
HighCVSS 7.8KEVWeaponizedEPSS 90%adobe · flash playerFeb 6, 2018
- CVE-2022-229486Now
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via
HighCVSS 8.8KEVWeaponizedEPSS 70%google · chromeJul 27, 2022
- CVE-2021-2122086Now
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit he
HighCVSS 8.8KEVWeaponizedEPSS 70%google · chromeApr 26, 2021
- CVE-2015-865185Now
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
HighCVSS 8.8KEVWeaponizedEPSS 68%adobe · air sdkDec 28, 2015
- CVE-2021-3055184Now
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 65%google · chromeJun 15, 2021
- CVE-2021-3063284Now
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a craf
HighCVSS 8.8KEVWeaponizedEPSS 63%google · chromeOct 8, 2021
- CVE-2019-221583Now
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.
HighCVSS 7.8KEVWeaponizedEPSS 72%google · androidOct 11, 2019
- CVE-2018-606583Now
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3
HighCVSS 8.8KEVWeaponizedEPSS 60%google · chromeNov 14, 2018
- CVE-2026-244182Now
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra
HighCVSS 8.8KEVWeaponizedEPSS 55%google · chromeFeb 13, 2026
- CVE-2016-098481Now
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2
HighCVSS 8.8KEVWeaponizedEPSS 55%adobe · flash playerFeb 10, 2016
- CVE-2020-1599981Now
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vi
CriticalCVSS 9.6KEVWeaponizedEPSS 44%google · chromeNov 2, 2020
- CVE-2011-060980Now
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on
HighCVSS 7.8KEVWeaponizedEPSS 64%adobe · flash playerMar 15, 2011
- CVE-2019-1372080Now
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a cra
HighCVSS 8.8KEVWeaponizedEPSS 49%google · chromeNov 25, 2019
- CVE-2023-521780Now
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten
HighCVSS 8.8KEVWeaponizedEPSS 49%google · chromeSep 28, 2023
- CVE-2026-8504680Now
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
HighCVSS 8.8KEVWeaponizedEPSS 49%google · chromeSep 3, 2026
- CVE-2020-1600979This week
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption
HighCVSS 8.8KEVWeaponizedEPSS 48%google · chromeNov 2, 2020
- CVE-2016-164679This week
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly cons
HighCVSS 8.8KEVWeaponizedEPSS 48%google · chromeMar 29, 2016