#CVSS Critical
All CosmicBytez Labs articles tagged #CVSS Critical, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-61514: Puwell IP Camera Authentication Bypass
A critical authentication bypass in Puwell IP Camera firmware 2.x through 4.x allows unauthenticated attackers to access live video streams, control...
- Security
CVE-2026-61515: Puwell IP Camera Unauthenticated Command Injection
A critical unauthenticated command injection vulnerability in Puwell IP Camera firmware 2.x through 4.x allows remote attackers to execute arbitrary OS...
- Security
CVE-2026-38158: Critical SQL Injection in UReport v2.2.9 (CVSS 9.8)
A critical SQL injection vulnerability in the /ureport/datasource/previewData endpoint of ureport v2.2.9 allows unauthenticated attackers to exfiltrate...
- Security
CVE-2026-37431: Beauty Parlour Management System SQL
A critical unauthenticated SQL injection vulnerability in Beauty Parlour Management System v1.1 allows attackers to dump the entire backend database via a...
- Security
CVE-2026-41583: ZEBRA Zcash Node Consensus Rule Bypass
A missing sighash validation in ZEBRA, the Rust-based Zcash node, allowed invalid V5 transactions to pass consensus checks — patched in zebrad 4.3.1 and...
- Security
CVE-2026-41588: RELATE Courseware Timing Attack in Authentication (CVSS 9.0)
A timing attack vulnerability in RELATE's check_sign_in_key() function could allow attackers to infer valid sign-in keys through response time differences...