Tag
critical
advisory
SiYuan Knowledge Management System RCE via Malicious Website
2 rules 1 TTP 1 CVESiYuan versions prior to 3.6.2 are vulnerable to remote code execution (RCE) via a malicious website exploiting a permissive CORS policy to inject a JavaScript snippet, leading to arbitrary code execution within the application's Node.js context.
cve-2026-34449
rce
siyuan
cors
2r
1t
1c
high
advisory
Glances XML-RPC Server Cross-Origin Information Disclosure
2 rules 3 TTPs 2 IOCsThe Glances XML-RPC server exposes sensitive system information due to a permissive CORS policy and missing Content-Type validation, enabling attackers to bypass CORS restrictions and steal data like hostnames, OS details, IP addresses, and process lists.
glances
cors
information-disclosure
vulnerability
2r
3t
2i