Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

46,786 known vulnerabilities

529
CRITICAL
1,510
HIGH
426
MEDIUM

Top Products

ar8035 643 ar8035 firmware 621 aqt1000 616 mdm9206 611 mdm9206 firmware 603 aqt1000 firmware 586 mdm9607 564 mdm9607 firmware 562 mdm9650 483 mdm9650 firmware 473
2,465 CVEs · Page 5/50
6.5
CVE-2025-21465

Information disclosure while processing the hash segment in an MBN file.

6.5
CVE-2025-21464

Information disclosure while reading data from an image using specified offset and size parameters.

7.8
CVE-2025-21461

Memory corruption when programming registers through virtual CDM.

7.8
CVE-2025-21458

Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.

6.1
CVE-2025-21457

Information disclosure while opening a fastrpc session when domain is not sanitized.

7.8
CVE-2025-21456

Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.

7.8
CVE-2025-21455

Memory corruption while submitting blob data to kernel space though IOCTL.

7.5
CVE-2025-21452

Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.

7.8
CVE-2025-27061

Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the vid

7.8
CVE-2025-27058

Memory corruption while processing packet data with exceedingly large packet.

7.5
CVE-2025-27057

Transient DOS while handling beacon frames with invalid IE header length.

7.8
CVE-2025-27056

Memory corruption during sub-system restart while processing clean-up to free up resources.

7.8
CVE-2025-27055

Memory corruption during the image encoding process.

7.8
CVE-2025-27052

Memory corruption while processing data packets in diag received from Unix clients.

7.8
CVE-2025-27051

Memory corruption while processing command message in WLAN Host.

7.8
CVE-2025-27050

Memory corruption while processing event close when client process terminates abruptly.

7.8
CVE-2025-27047

Memory corruption while processing the TESTPATTERNCONFIG escape path.

7.8
CVE-2025-27046

Memory corruption while processing multiple simultaneous escape calls.

7.8
CVE-2025-27044

Memory corruption while executing timestamp video decode command with large input values.

7.8
CVE-2025-27043

Memory corruption while processing manipulated payload in video firmware.

7.8
CVE-2025-27042

Memory corruption while processing video packets received from video firmware.

7.8
CVE-2025-21466

Memory corruption while processing a private escape command in an event trigger.

7.5
CVE-2025-21454

Transient DOS while processing received beacon frame.

9.1
CVE-2025-21450

Cryptographic issue occurs due to use of insecure connection method while downloading.

7.5
CVE-2025-21449

Transient DOS may occur while processing malformed length field in SSID IEs.

7.5
CVE-2025-21446

Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests

7.8
CVE-2025-21445

Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the

7.8
CVE-2025-21444

Memory corruption while copying the result to the transmission queue in EMAC.

6.2
CVE-2025-21433

Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

7.8
CVE-2025-21432

Memory corruption while retrieving the CBOR data from TA.

8.2
CVE-2025-21427

Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

6.6
CVE-2025-21426

Memory corruption while processing camera TPG write request.

7.1
CVE-2025-21422

Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.

5.3
CVE-2024-53009

Memory corruption while operating the mailbox in Automotive.

8.6
CVE-2025-21479 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

7.5
CVE-2025-27038 KEV

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

7.8
CVE-2025-27031

memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.

7.5
CVE-2025-27029

Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.

7.8
CVE-2025-21486

Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.

7.8
CVE-2025-21485

Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.

8.6
CVE-2025-21480 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

7.5
CVE-2025-21463

Transient DOS while processing the EHT operation IE in the received beacon frame.

8.2
CVE-2024-53026

Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.

8.2
CVE-2024-53021

Information disclosure may occur while processing goodbye RTCP packet from network.

8.2
CVE-2024-53020

Information disclosure may occur while decoding the RTP packet with invalid header extension from network.

8.2
CVE-2024-53019

Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing so

6.6
CVE-2024-53018

Memory corruption may occur while processing the OIS packet parser.

6.6
CVE-2024-53017

Memory corruption while handling test pattern generator IOCTL command.

6.6
CVE-2024-53016

Memory corruption while processing I2C settings in Camera driver.

6.6
CVE-2024-53015

Memory corruption while processing IOCTL command to handle buffers associated with a session.

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started