Aggregator
朱雀三号可重复使用火箭通过静态点火试验
3 months 2 weeks ago
蓝箭航天本周完成了朱雀三号遥一运载火箭首飞任务的第一阶段工作——加注合练及静态点火试验,为今年晚些时候第二阶段的试飞和第一级回收做准备。朱雀三号一二级箭体直径 4.5 米,整流罩直径 5.2 米,全箭长 66.1 米,起飞质量约 570 吨,起飞推力超过 750 吨,采用不锈钢作为箭体主结构材料,一子级配备九台天鹊-12A液氧甲烷发动机,设计可在执行轨道发射任务后自主高精度返回,在回收场实现软着陆并重复使用。火箭如果是一次性使用其有效载荷为 11,800 公斤,如果尝试回收第一级则有效载荷为 8,000 公斤。相比下 SpaceX 的 Falcon 9 能将 22,800 公斤负荷发射到低地球轨道。
CVE-2025-62641
3 months 2 weeks ago
Currently trending CVE - Hype Score: 1 - Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox ...
Росатом выпустил робота-"паучка" в радиоактивные недра АЭС — и он охотится за невидимыми трещинами втрое быстрее человека
3 months 2 weeks ago
Автоматический дефектоскоп проникает в узкие полости реакторов, где людям грозит смертельное облучение.
香港中文大学|薛棣文老师招生信息
3 months 2 weeks ago
薛棣文老师招收安全/网络/测量 方向博士生/RA/访问学者
Qilin
3 months 2 weeks ago
You must login to view this content
cohenido
Qilin
3 months 2 weeks ago
You must login to view this content
cohenido
CVE-2025-11897 | The7 Plugin up to 12.9.1 on WordPress the7_fancy_title_css cross site scripting
3 months 2 weeks ago
A vulnerability described as problematic has been identified in The7 Plugin up to 12.9.1 on WordPress. This impacts the function the7_fancy_title_css. Executing manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2025-11897. The attack can be executed remotely. There is not any exploit available.
vuldb.com
Pwn2Own Ireland 2025: The Hacks, The Winners, and The Big Payouts
3 months 2 weeks ago
Hackers earned over $1 million at Pwn2Own Ireland 2025 in Cork, breaching printers, routers, NAS devices, and more as Summoning Team claimed Master of Pwn.
Waqas
Telnet, HTTP и UPnP всё ещё включены? Чеклист базовой защиты маршрутизатора для тех, кто не хочет проблем
3 months 2 weeks ago
Как отключить лишние сервисы, включить безопасные протоколы и ограничить доступ.
Не верьте ботам. Представлена техника AI Sidebar Spoofing: хакеры подменяют ИИ-панели для кражи паролей
3 months 2 weeks ago
Одного расширения достаточно, чтобы захватить компьютер.
CVE-2025-46334 | Microsoft Visual Studio Git privilege escalation (EUVD-2025-21003 / Nessus ID 271351)
3 months 2 weeks ago
A vulnerability classified as problematic has been found in Microsoft Visual Studio. This affects an unknown function of the component Git. This manipulation causes privilege escalation.
This vulnerability appears as CVE-2025-46334. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2025-46334 | j6t git-gui up to 2.50.0 sh.exe os command injection (GHSA-7px4-9hg2-fvhx / EUVD-2025-21003)
3 months 2 weeks ago
A vulnerability was found in j6t git-gui up to 2.50.0 and classified as critical. Affected by this issue is some unknown functionality of the file sh.exe. Such manipulation leads to os command injection.
This vulnerability is listed as CVE-2025-46334. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2022-31782 | Freedesktop FreeType Demo Programs up to 2.12.1 ftbench.c heap-based overflow (Nessus ID 271354)
3 months 2 weeks ago
A vulnerability has been found in Freedesktop FreeType Demo Programs up to 2.12.1 and classified as critical. Affected is an unknown function of the file ftbench.c. This manipulation causes heap-based buffer overflow.
This vulnerability is handled as CVE-2022-31782. The attack can only be done within the local network. There is not any exploit available.
vuldb.com
CVE-2025-53052 | Oracle Workflow up to 12.2.14 Workflow Notification Mailer access control (Nessus ID 271365)
3 months 2 weeks ago
A vulnerability was found in Oracle Workflow up to 12.2.14 and classified as critical. Impacted is an unknown function of the component Workflow Notification Mailer. Executing manipulation can lead to improper access controls.
This vulnerability appears as CVE-2025-53052. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-53058 | Oracle Applications Manager up to 12.2.14 Application Logging Interface access control (Nessus ID 271365)
3 months 2 weeks ago
A vulnerability was found in Oracle Applications Manager up to 12.2.14. It has been declared as critical. The impacted element is an unknown function of the component Application Logging Interface. The manipulation results in improper access controls.
This vulnerability is known as CVE-2025-53058. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21721 | Linux Kernel up to 6.12.12/6.13.1 nilfs2 nilfs_prepare_chunk buffer overflow (Nessus ID 230658 / WID-SEC-2025-0453)
3 months 2 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.12.12/6.13.1. This vulnerability affects the function nilfs_prepare_chunk of the component nilfs2. This manipulation causes buffer overflow.
This vulnerability is handled as CVE-2025-21721. The attack can only be done within the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21723 | Linux Kernel up to 6.12.12/6.13.1 bsg_setup_queue null pointer dereference (Nessus ID 236983 / WID-SEC-2025-0453)
3 months 2 weeks ago
A vulnerability has been found in Linux Kernel up to 6.12.12/6.13.1 and classified as critical. This affects the function bsg_setup_queue. This manipulation causes null pointer dereference.
This vulnerability is handled as CVE-2025-21723. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-21722 | Linux Kernel up to 6.1.128/6.12.12/6.13.1 fs/buffer.c mark_buffer_dirty use after free (Nessus ID 233595 / WID-SEC-2025-0453)
3 months 2 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.128/6.12.12/6.13.1. This issue affects the function mark_buffer_dirty of the file fs/buffer.c. Such manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2025-21722. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-21720 | Linux Kernel up to 6.6.75/6.12.12/6.13.1 Netlink Socket ip_forward null pointer dereference (Nessus ID 236983 / WID-SEC-2025-0453)
3 months 2 weeks ago
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.6.75/6.12.12/6.13.1. This impacts an unknown function of the file /proc/sys/net/ipv4/ip_forward of the component Netlink Socket Handler. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-21720. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com