Qualcomm vendor intelligence
Qualcomm Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Qualcomm products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 13
- Known exploited vulnerabilities affecting Qualcomm products
- In CISA KEV
- 13
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Qualcomm KEVs with sensor-observed exploitation activity
The catalog gap matters for Qualcomm exposure
All thirteen exploited Qualcomm CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
- 4
- Product families
Attested Qualcomm CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-21385
Integer Overflow or Wraparound in Graphics |
Snapdragon | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-27038
Use After Free in Graphics |
Snapdragon | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21480
Incorrect Authorization in Graphics Windows |
Snapdragon | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21479
Incorrect Authorization in Graphics |
Snapdragon | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-1905
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute,... |
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-1906
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute,... |
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-11261
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto,... |
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | Confirmed | In CISA | 01 Dec 2021 |
|
CVE-2013-2597
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in... |
Linux Kernel | Confirmed | In CISA | 15 Sep 2022 |
|
CVE-2022-22071
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto,... |
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music | Confirmed | In CISA | 05 Dec 2023 |
|
CVE-2023-33063
Use After Free in DSP Services |
Snapdragon | Confirmed | In CISA | 05 Dec 2023 |
|
CVE-2023-33106
Use of Out-of-range Pointer Offset in Graphics |
Snapdragon | Confirmed | In CISA | 05 Dec 2023 |
|
CVE-2023-33107
Integer Overflow or Wraparound in Graphics Linux |
Snapdragon | Confirmed | In CISA | 05 Dec 2023 |
|
CVE-2024-43047
Use After Free in DSP Service |
Snapdragon | Confirmed | In CISA | 08 Oct 2024 |
No Qualcomm CVEs match this search or filter.
Showing 13 of 13 Qualcomm known exploited vulnerabilities.
Recurring weakness patterns
Use after free, integer overflow or wraparound, and incorrect authorization account for nine mapped occurrences across this Qualcomm KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.