boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Qualcomm

Vendor reference — Qualcomm · sector: Other. Cumulative disclosure record across the archive.

Follow Qualcomm — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs7665
KEV entries121
Rate & severity
KEV/100Med CVSSMed EPSSCHML
15.87.8.0010258160

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁█▅▅▇▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-0622
2026-0711
2026-0811
2026-0920
2026-100

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2020-112617.875.0HIGHYES2021-06-09
CVE-2021-19058.474.1HIGHYES2021-05-07
CVE-2026-213857.868.7HIGHYES2026-03-02
CVE-2025-270387.562.1HIGHYES2025-06-03
CVE-2025-214798.656.5HIGHYES2025-06-03
CVE-2023-331068.453.3HIGHYES2023-12-05
CVE-2023-331078.452.4HIGHYES2023-12-05
CVE-2024-430477.850.4HIGHYES2024-10-07
CVE-2023-330637.845.1HIGHYES2023-12-05
CVE-2021-19066.242.1MEDIUMYES2021-05-07
CVE-2025-214808.637.6HIGHYES2025-06-03
CVE-2022-220718.437.3HIGHYES2022-06-14
CVE-2026-252549.822.8CRITICAL—2026-09-22
CVE-2026-240847.514.9HIGH—2026-08-04
CVE-2026-252626.910.9MEDIUM—2026-09-22

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-252658.80.1HIGH—2026-09-22
CVE-2026-252648.80.1HIGH—2026-09-22
CVE-2026-252626.910.9MEDIUM—2026-09-22
CVE-2026-252558.81.6HIGH—2026-09-22
CVE-2026-252549.822.8CRITICAL—2026-09-22
CVE-2026-252907.80.0HIGH—2026-09-17
CVE-2026-252947.40.8HIGH—2026-09-17
CVE-2026-252847.30.0HIGH—2026-09-17
CVE-2026-240747.80.0HIGH—2026-09-17
CVE-2026-240737.80.0HIGH—2026-09-17
CVE-2025-596077.80.0HIGH—2026-09-17
CVE-2026-252838.80.0HIGH—2026-09-17
CVE-2026-252827.90.0HIGH—2026-09-17
CVE-2026-252787.00.0HIGH—2026-09-17
CVE-2026-252817.40.8HIGH—2026-09-17

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-213852026-03-037.868.7HIGH
CVE-2025-270382025-06-037.562.1HIGH
CVE-2025-214802025-06-038.637.6HIGH
CVE-2025-214792025-06-038.656.5HIGH
CVE-2024-430472024-10-087.850.4HIGH
CVE-2022-220712023-12-058.437.3HIGH
CVE-2023-330632023-12-057.845.1HIGH
CVE-2023-331062023-12-058.453.3HIGH
CVE-2023-331072023-12-058.452.4HIGH
CVE-2020-112612021-12-017.875.0HIGH
CVE-2021-19052021-11-038.474.1HIGH
CVE-2021-19062021-11-036.242.1MEDIUM

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2021-19062021-11-171782
CVE-2021-19052022-05-031615
CVE-2020-112612022-06-011586
CVE-2023-331072023-12-261013
CVE-2023-331062023-12-261013
CVE-2023-330632023-12-261013
CVE-2022-220712023-12-261013
CVE-2024-430472024-10-29705
CVE-2025-214792025-06-24467
CVE-2025-214802025-06-24467

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.