A vulnerability classified as critical was found in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manipulation of the argument viewfile can lead to unrestricted upload.
This vulnerability appears as CVE-2026-1107. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical has been found in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of the component Legal Consent Handler. Performing a manipulation of the argument userId results in improper authorization.
This vulnerability is reported as CVE-2026-1106. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability described as critical has been identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of the argument _order leads to sql injection.
This vulnerability is documented as CVE-2026-1105. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
OpenAI on Friday said it would start showing ads in ChatGPT to logged-in adult U.S. users in both the free and ChatGPT Go tiers in the coming weeks, as the artificial intelligence (AI) company expanded access to its low-cost subscription globally.
"You need to know that your data and conversations are protected and never sold to advertisers," OpenAI said. "And we need to keep a high bar and give
A vulnerability marked as problematic has been reported in Gradle up to 9.2.x. This affects an unknown part. This manipulation causes download of code without integrity check.
This vulnerability is registered as CVE-2026-22865. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability labeled as problematic has been found in Gradle up to 9.2.x. Affected by this issue is some unknown functionality. The manipulation results in inclusion of functionality from untrusted control sphere.
This vulnerability is cataloged as CVE-2026-22816. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in Absolute Security Secure Access up to 14.19. Affected by this vulnerability is an unknown functionality of the component Packet Handler. The manipulation leads to denial of service.
This vulnerability is listed as CVE-2026-0517. The attack must be carried out from within the local network. There is no available exploit.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Absolute Security Secure Access up to 14.19. Affected is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-0518. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Absolute Security Secure Access up to 14.19. It has been rated as problematic. This impacts an unknown function of the component Authentication Token Handler. Performing a manipulation results in sensitive information in log files.
This vulnerability is identified as CVE-2026-0519. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is advised.