Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

46,786 known vulnerabilities

529
CRITICAL
1,510
HIGH
426
MEDIUM

Top Products

ar8035 643 ar8035 firmware 621 aqt1000 616 mdm9206 611 mdm9206 firmware 603 aqt1000 firmware 586 mdm9607 564 mdm9607 firmware 562 mdm9650 483 mdm9650 firmware 473
2,465 CVEs · Page 4/50
7.8
CVE-2025-47338

Memory corruption while processing escape commands from userspace.

8.8
CVE-2025-27060

Memory corruption while performing SCM call with malformed inputs.

8.8
CVE-2025-27059

Memory corruption while performing SCM call.

7.8
CVE-2025-27054

Memory corruption while processing a malformed license file during reboot.

7.8
CVE-2025-27053

Memory corruption during PlayReady APP usecase while processing TA commands.

5.5
CVE-2025-27049

Transient DOS while processing IOCTL call for image encoding.

7.8
CVE-2025-27048

Memory corruption while processing camera platform driver IOCTL calls.

6.1
CVE-2025-27045

Information disclosure while processing batch command execution in Video driver.

5.5
CVE-2025-27041

Transient DOS while processing video packets received from video firmware.

6.5
CVE-2025-27040

Information disclosure may occur while processing the hypervisor log.

6.6
CVE-2025-27039

Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.

7.8
CVE-2025-47329

Memory corruption while handling invalid inputs in application info setup.

7.5
CVE-2025-47328

Transient DOS while processing power control requests with invalid antenna or stream values.

7.8
CVE-2025-47327

Memory corruption while encoding the image data.

7.5
CVE-2025-47326

Transient DOS while handling command data during power control processing.

7.5
CVE-2025-47318

Transient DOS while parsing the EPTM test control message to get the test pattern.

7.8
CVE-2025-47317

Memory corruption due to global buffer overflow when a test command uses an invalid payload type.

7.8
CVE-2025-47316

Memory corruption due to double free when multiple threads race to set the timestamp store.

7.8
CVE-2025-47315

Memory corruption while handling repeated memory unmap requests from guest VM.

7.8
CVE-2025-47314

Memory corruption while processing data sent by FE driver.

7.8
CVE-2025-27077

Memory corruption while processing message in guest VM.

7.8
CVE-2025-27037

Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.

6.1
CVE-2025-27036

Information disclosure when Video engine escape input data is less than expected minimum size.

9.8
CVE-2025-27034

Memory corruption while selecting the PLMN from SOR failed list.

6.1
CVE-2025-27033

Information disclosure while running video usecase having rogue firmware.

7.8
CVE-2025-27032

memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache

6.1
CVE-2025-27030

information disclosure while invoking calibration data from user space to update firmware size.

8.2
CVE-2025-21488

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is se

8.2
CVE-2025-21487

Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is great

8.2
CVE-2025-21484

Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments f

9.8
CVE-2025-21483

Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.

7.1
CVE-2025-21482

Cryptographic issue while performing RSA PKCS padding decoding.

7.8
CVE-2025-21481

Memory corruption while performing private key encryption in trusted application.

7.8
CVE-2025-21476

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

7.5
CVE-2025-47324

Information disclosure while accessing and modifying the PIB file of a remote device via powerline.

7.8
CVE-2025-27076

Memory corruption while processing simultaneous requests via escape path.

7.8
CVE-2025-27075

Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.

7.5
CVE-2025-27073

Transient DOS while creating NDP instance.

5.5
CVE-2025-27072

Information disclosure while processing a packet at EAVB BE side with invalid header length.

7.3
CVE-2025-27071

Memory corruption while processing specific files in Powerline Communication Firmware.

7.8
CVE-2025-27069

Memory corruption while processing DDI command calls.

7.8
CVE-2025-27068

Memory corruption while processing an IOCTL command with an arbitrary address.

7.8
CVE-2025-27067

Memory corruption while processing DDI call with invalid buffer.

7.5
CVE-2025-27066

Transient DOS while processing an ANQP message.

7.5
CVE-2025-27065

Transient DOS while processing a frame with malformed shared-key descriptor.

7.8
CVE-2025-27062

Memory corruption while handling client exceptions, allowing unauthorized channel access.

7.5
CVE-2025-21477

Transient DOS while processing CCCH data when NW sends data with invalid length.

7.8
CVE-2025-21474

Memory corruption while processing commands from A2dp sink command queue.

7.8
CVE-2025-21473

Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.

5.5
CVE-2025-21472

Information disclosure while capturing logs as eSE debug messages are logged.

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28761 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 9787 critical severity (CVSS 9.0+) and 28761 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started