Qualcomm Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Qualcomm products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

13

In CISA KEV

13

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Qualcomm KEVs Added by Year

Loading...

13 Qualcomm KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-21385

Integer Overflow or Wraparound in Graphics

Confirmed In CISA 01 Jun 2026
CVE-2025-27038

Use After Free in Graphics

Confirmed In CISA 01 Jun 2026
CVE-2025-21480

Incorrect Authorization in Graphics Windows

Confirmed In CISA 01 Jun 2026
CVE-2025-21479

Incorrect Authorization in Graphics

Confirmed In CISA 01 Jun 2026
CVE-2021-1905

Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute,...

Confirmed In CISA 03 Nov 2021
CVE-2021-1906

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute,...

Confirmed In CISA 03 Nov 2021
CVE-2020-11261

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto,...

Confirmed In CISA 01 Dec 2021
CVE-2013-2597

Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in...

Confirmed In CISA 15 Sep 2022
CVE-2022-22071

Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto,...

Confirmed In CISA 05 Dec 2023
CVE-2023-33063

Use After Free in DSP Services

Confirmed In CISA 05 Dec 2023
CVE-2023-33106

Use of Out-of-range Pointer Offset in Graphics

Confirmed In CISA 05 Dec 2023
CVE-2023-33107

Integer Overflow or Wraparound in Graphics Linux

Confirmed In CISA 05 Dec 2023
CVE-2024-43047

Use After Free in DSP Service

Confirmed In CISA 08 Oct 2024

Common Vulnerability Classes (CWE)

  • CWE-416 — Use After Free 5
  • CWE-190 — Integer Overflow or Wraparound 2
  • CWE-863 — Incorrect Authorization 2
  • CWE-121 — Stack-based Buffer Overflow 1
  • CWE-20 — Improper Input Validation 1
  • CWE-823 — Use of Out-of-range Pointer Offset 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology