CVE-2026-7632
published 2026-05-02CVE-2026-7632: A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This…
PriorityP343high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.27%
18.6th percentile
A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | online_hospital_management_system | — | — |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc9.6CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2crf-7pw9-c88r: A vulnerability was determined in code-projects Online Hospital Management System 1
ghsa_unreviewed·2026-05-02
CVE-2026-7632 [MEDIUM] CWE-74 GHSA-2crf-7pw9-c88r: A vulnerability was determined in code-projects Online Hospital Management System 1
A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Microsoft
Chromium: CVE-2026-3545 Insufficient data validation in Navigation
vendor_msrc·2026-03-10·CVSS 9.6
CVE-2026-3545 [CRITICAL] Chromium: CVE-2026-3545 Insufficient data validation in Navigation
Chromium: CVE-2026-3545 Insufficient data validation in Navigation
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
145.0.3800.97
03/06/2026
145.0.7632.159/160
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version
Red Hat
chromium-browser: Integer overflow in ANGLE
vendor_redhat·2026-03-03·CVSS 8.8
CVE-2026-3536 [HIGH] chromium-browser: Integer overflow in ANGLE
chromium-browser: Integer overflow in ANGLE
Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
An integer overflow flaw was found in the ANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=485622239
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Object lifecycle issue in DevTools
vendor_redhat·2026-03-03·CVSS 8.8
CVE-2026-3539 [HIGH] chromium-browser: Object lifecycle issue in DevTools
chromium-browser: Object lifecycle issue in DevTools
Object lifecycle issue in DevTools in Google Chrome prior to 145.0.7632.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
An object lifecycle issue flaw was found in the DevTools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=483853098
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Inappropriate implementation in DevTools
vendor_redhat·2026-02-23·CVSS 5.4
CVE-2026-3063 [MEDIUM] chromium-browser: Inappropriate implementation in DevTools
chromium-browser: Inappropriate implementation in DevTools
Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. (Chromium security severity: High)
An inappropriate implementation flaw was found in the DevTools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=485287859
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
chromium-browser: Inappropriate implementation in Animation
vendor_redhat·2026-02-10·CVSS 6.5
CVE-2026-2317 [MEDIUM] chromium-browser: Inappropriate implementation in Animation
chromium-browser: Inappropriate implementation in Animation
Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
An inappropriate implementation flaw was found in the Animation component of the Chromium browser.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Microsoft
Chromium: CVE-2026-2648 Heap buffer overflow in PDFium
vendor_msrc·2026-02-10·CVSS 8.8
CVE-2026-2648 [HIGH] Chromium: CVE-2026-2648 Heap buffer overflow in PDFium
Chromium: CVE-2026-2648 Heap buffer overflow in PDFium
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
145.0.3800.70
02/20/2026
145.0.7632.109/110
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the brow
Microsoft
Chromium: CVE-2026-2649 Integer overflow in V8
vendor_msrc·2026-02-10·CVSS 8.8
CVE-2026-2649 [HIGH] Chromium: CVE-2026-2649 Integer overflow in V8
Chromium: CVE-2026-2649 Integer overflow in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
145.0.3800.70
02/20/2026
145.0.7632.109/110
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
No detection rules found.
No public exploits indexed.
2026-05-02
Published