CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “arm”

686 vulnerabilities found for “arm”

Page 1 of 35

CVE-2025-0647
HIGH7.9

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.

arm / c1-ultra_firmware+10
Local
Published Jan 14, 2026
Page 1 of 35
CVE-2024-7881
MEDIUM5.1

An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced.

arm / c1-premium_firmware+8
Local
Published Jan 28, 2025
CVE-2024-10929
MEDIUM5.1

In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.

arm / cortex-a57_firmware+3
Local
Published Jan 22, 2025
CVE-2024-5660
CRITICAL9.8

Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2 translation and/or GPT protection.

arm / cortex-a710_firmware+15
Network
Published Dec 10, 2024
CVE-2023-0918
MEDIUM6.3

A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file add.php of the component Avatar Image Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221494 is the identifier assigned to this vulnerability.

pharmacy_management_system_project / pharmacy_management_system
Network
Published Feb 19, 2023
CVE-2022-48251
HIGH7.5

The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."

arm / cortex-a53_firmware+9
Network
Published Jan 10, 2023
CVE-2022-38699
MEDIUM5.9

Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.

asus / armoury_crate_service
Physical
Published Sep 28, 2022
CVE-2022-34949
CRITICAL9.8

Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php.

pharmacy_management_system_project / pharmacy_management_system
Network
Published Aug 2, 2022
CVE-2022-34945
CRITICAL9.8

Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.

pharmacy_management_system_project / pharmacy_management_system
Network
Published Aug 2, 2022
CVE-2022-34948
CRITICAL9.8

Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php.

pharmacy_management_system_project / pharmacy_management_system
Network
Published Aug 2, 2022
CVE-2022-34947
CRITICAL9.8

Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php.

pharmacy_management_system_project / pharmacy_management_system
Network
Published Aug 2, 2022
CVE-2022-34950
CRITICAL9.8

Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php.

pharmacy_management_system_project / pharmacy_management_system
Network
Published Aug 2, 2022
CVE-2022-34946
CRITICAL9.8

Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.

pharmacy_management_system_project / pharmacy_management_system
Network
Published Aug 2, 2022
CVE-2022-30887
CRITICAL9.8

Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.

pharmacy_management_system_project / pharmacy_management_system
Network
Published May 20, 2022
CVE-2022-23960
MEDIUM5.6

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

xen / xen+22
Local
Published Mar 13, 2022
CVE-2022-25368
MEDIUM4.7

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.

amperecomputing / ampere_altra_max_firmware+21
Local
Published Mar 10, 2022
CVE-2021-35465
LOW3.4

Certain Arm products before 2021-08-23 do not properly consider the effect of exceptions on a VLLDM instruction. A Non-secure handler may have read or write access to part of a Secure context. This affects Arm Cortex-M33 r0p0 through r1p0, Arm Cortex-M35P r0, Arm Cortex-M55 r0p0 through r1p0, and Arm China STAR-MC1 (in the STAR SE configuration).

arm / cortex-m33_firmware+3
Local
Published Aug 23, 2021
CVE-2020-10286
HIGH8.8

the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.

ufactory / xarm_5_lite_firmware+2
Adjacent
Published Jul 15, 2020
CVE-2020-13844
MEDIUM5.5

Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."

arm / cortex-a32_firmware+8
Local
Published Jun 8, 2020
CVE-2017-5753
MEDIUM5.6

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

intel / core_i5+999
Local
Published Jan 4, 2018