CyberMax
Home › Exploited CVEs › Qualcomm

Qualcomm Multiple Chipsets known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 10 Qualcomm Multiple Chipsets CVEs as exploited in the wild. 1 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 10 Qualcomm Multiple Chipsets CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2021-1905Multiple Chipsets Use-After-Free1.5%–2021-11-032022-05-03
2CVE-2026-21385Multiple Chipsets Memory Corruption1.3%–2026-03-032026-03-24
3CVE-2025-27038Multiple Chipsets Use-After-Free1.0%–2025-06-032025-06-24
4CVE-2023-33106Multiple Chipsets Use of Out-of-Range Pointer Offset0.9%–2023-12-052023-12-26
5CVE-2023-33107Multiple Chipsets Integer Overflow0.9%–2023-12-052023-12-26
6CVE-2025-21479Multiple Chipsets Incorrect Authorization0.8%–2025-06-032025-06-24
7CVE-2023-33063Multiple Chipsets Use-After-Free0.7%–2023-12-052023-12-26
8CVE-2021-1906Multiple Chipsets Detection of Error Condition Without Action0.5%–2021-11-032021-11-17
9CVE-2025-21480Multiple Chipsets Incorrect Authorization0.5%–2025-06-032025-06-24
10CVE-2022-22071Multiple Chipsets Use-After-Free0.5%–2023-12-052023-12-26
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Qualcomm KEV CVEs · free KEV badge for Qualcomm · all vendors