CVE-2026-7732
published 2026-05-04CVE-2026-7732: A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The…
PriorityP342medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.21%
10.6th percentile
A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | bloodbank_managing_system | — | — |
| linux | linux_kernel | >= 6.13.0 < 6.18.6 | 6.18.6 |
| linux | linux_kernel | >= 6.7.0 < 6.12.66 | 6.12.66 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c98h-86g2-c8j3: A vulnerability was detected in code-projects BloodBank Managing System 1
ghsa_unreviewed·2026-05-04
CVE-2026-7732 [LOW] CWE-284 GHSA-c98h-86g2-c8j3: A vulnerability was detected in code-projects BloodBank Managing System 1
A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.
VulDB
code-projects BloodBank Managing System 1.0 request_blood.php unrestricted upload
vuldb·2026-05-03
CVE-2026-7732 [CRITICAL] code-projects BloodBank Managing System 1.0 request_blood.php unrestricted upload
A vulnerability classified as critical was found in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload.
This vulnerability is identified as CVE-2026-7732. The attack can be executed remotely. Additionally, an exploit exists.
OSV
idpf: fix memory leak in idpf_vport_rel()
osv·2026-01-31·CVSS 5.5
CVE-2026-23023 idpf: fix memory leak in idpf_vport_rel()
idpf: fix memory leak in idpf_vport_rel()
In the Linux kernel, the following vulnerability has been resolved:
idpf: fix memory leak in idpf_vport_rel()
Free vport->rx_ptype_lkup in idpf_vport_rel() to avoid leaking memory
during a reset. Reported by kmemleak:
unreferenced object 0xff450acac838a000 (size 4096):
comm "kworker/u258:5", pid 7732, jiffies 4296830044
hex dump (first 32 bytes):
00 00 00 00 00 10 00 00 00 10 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 ................
backtrace (crc 3da81902):
__kmalloc_cache_noprof+0x469/0x7a0
idpf_send_get_rx_ptype_msg+0x90/0x570 [idpf]
idpf_init_task+0x1ec/0x8d0 [idpf]
process_one_work+0x226/0x6d0
worker_thread+0x19e/0x340
kthread+0x10f/0x250
ret_from_fork+0x251/0x2b0
ret_from_fork_asm+0x1a/0x30
Red Hat
kernel: Linux kernel: Memory leak in idpf driver can lead to denial of service
vendor_redhat·2026-01-31·CVSS 5.5
CVE-2026-23023 [MEDIUM] CWE-772 kernel: Linux kernel: Memory leak in idpf driver can lead to denial of service
kernel: Linux kernel: Memory leak in idpf driver can lead to denial of service
In the Linux kernel, the following vulnerability has been resolved:
idpf: fix memory leak in idpf_vport_rel()
Free vport->rx_ptype_lkup in idpf_vport_rel() to avoid leaking memory
during a reset. Reported by kmemleak:
unreferenced object 0xff450acac838a000 (size 4096):
comm "kworker/u258:5", pid 7732, jiffies 4296830044
hex dump (first 32 bytes):
00 00 00 00 00 10 00 00 00 10 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 ................
backtrace (crc 3da81902):
__kmalloc_cache_noprof+0x469/0x7a0
idpf_send_get_rx_ptype_msg+0x90/0x570 [idpf]
idpf_init_task+0x1ec/0x8d0 [idpf]
process_one_work+0x226/0x6d0
worker_thread+0x19e/0x340
kthread+0x10f/0x250
ret_from_fork+0x251/0x2b0
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-04
Published