Unisoc (Shanghai) Technologies Co., Ltd.

First CVE: Sep 9, 2022Active for: 4 years
648
CVEs Published
More CVEs Published than 88% of tracked CNAs
129.6
Avg CVEs / Year
More Avg CVEs / Year than 91% of tracked CNAs
5.8
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA, 97.7% affect products that Unisoc (Shanghai) Technologies Co., Ltd. develops as a vendor.

97.7%
Self-reported: 633Third-party: 15

Of all the CVEs published that affect products developed by Unisoc (Shanghai) Technologies Co., Ltd., 99.7% are self-published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA.

99.7%
Self-published: 633Published by other CNAs: 2

Trends Over Time

The number and severity of CVEs published by Unisoc (Shanghai) Technologies Co., Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2022
3 years ago
Most Recent CVE
Jul 3, 2026
21 days ago

Top CVEs

All CVEs published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA, regardless of affected vendor or product.

648 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed.
Jul 3, 20267.535NONO
In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges
Aug 18, 20259.834NONO
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.533NONO
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.533NONO
In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
Sep 1, 20259.833NONO
In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without requiring additional execution privileges
Sep 1, 20259.833NONO
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.532NONO
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.530NONO
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.530NONO
In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
May 6, 20267.530NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA648 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local600 (92.6%)
Network45 (6.9%)
Unknown0 (0.0%)
Physical1 (0.2%)
Adjacent Network2 (0.3%)
Attack Complexity
Low641 (98.9%)
High7 (1.1%)
Unknown0 (0.0%)
User Interaction
None646 (99.7%)
Unknown0 (0.0%)
Required2 (0.3%)
Privileges Required
Low479 (73.9%)
High114 (17.6%)
None55 (8.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (648 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Unisoc (Shanghai) Technologies Co., Ltd. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs