Google LLC

First CVE: Mar 26, 2020Active for: 6 years
582
CVEs Published
More CVEs Published than 87% of tracked CNAs
83.1
Avg CVEs / Year
More Avg CVEs / Year than 89% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked CNAs
1.4%
In CISA KEV
Higher KEV Rate than 89% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Google LLC as a CNA, 72.3% affect products that Google LLC develops as a vendor.

72.3%
27.7%
Self-reported: 421Third-party: 161

Of all the CVEs published that affect products developed by Google LLC, 2.7% are self-published by Google LLC as a CNA.

97.3%
Self-published: 421Published by other CNAs: 14,989

Trends Over Time

The number and severity of CVEs published by Google LLC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2020
6 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Google LLC as a CNA, regardless of affected vendor or product.

582 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerabili
May 24, 20239.897YESYES
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory
Jul 7, 20217.896YESYES
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code
Dec 1, 20229.890NOYES
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corrupti
Jul 15, 20257.780NOYES
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows
Jan 31, 20247.879YESNO
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti
Jun 13, 20247.866YESNO
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti
Apr 5, 20247.865YESNO
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgr
Jan 26, 20227.064YESNO
A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that ca
Jan 30, 20237.062YESNO
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interacti
Apr 5, 20245.557YESNO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA582 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local341 (58.6%)
Network207 (35.6%)
Unknown0 (0.0%)
Physical5 (0.9%)
Adjacent Network18 (3.1%)
Attack Complexity
Low527 (90.5%)
High55 (9.5%)
Unknown0 (0.0%)
User Interaction
None518 (89.0%)
Unknown0 (0.0%)
Required49 (8.4%)
Privileges Required
Low313 (53.8%)
High22 (3.8%)
None247 (42.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (582 CVEs).

CISA KEV
8 CVEs
1.4% of CVEs· 89th percentile
Metasploit
3 CVEs
0.5% of CVEs· 82nd percentile
Nuclei
1 CVE
0.2% of CVEs· 71st percentile
ExploitDB
5 CVEs
0.9% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Google LLC as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Google LLC as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs