Vendorsnicolargoglancesall versions
Vulnerabilities

nicolargo (Nicolas Hennion) Glances

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-30930
Glances has SQL Injection via Process Names in TimescaleDB Export
Published 2026-03-10 · Analyzed
9.8EPSS 0.004
CVE-2026-32633
Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
Published 2026-03-18 · Analyzed
9.1EPSS 0.006
CVE-2026-32611
Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
Published 2026-03-18 · Analyzed
9.1EPSS 0.004
CVE-2026-35587
Glances IP Plugin has SSRF via public_api that leads to credential leakage
Published 2026-04-20 · Analyzed
8.8EPSS 0.005
CVE-2026-32596
Glances exposes the REST API without authentication
Published 2026-03-18 · Analyzed
8.7EPSS 0.017
CVE-2026-30928
Glances Exposes Unauthenticated Configuration Secrets
Published 2026-03-10 · Analyzed
8.7EPSS 0.016
CVE-2026-32610
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
Published 2026-03-18 · Analyzed
8.1EPSS 0.005
CVE-2026-32634
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
Published 2026-03-18 · Analyzed
8.1EPSS 0.002
CVE-2026-33641
Glances Vulnerable to Command Injection via Dynamic Configuration Values
Published 2026-04-02 · Analyzed
7.81 PoCEPSS 0.008
CVE-2026-34839
Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
Published 2026-04-20 · Analyzed
7.7EPSS 0.005
CVE-2026-32609
Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
Published 2026-03-18 · Analyzed
7.5EPSS 0.006
CVE-2026-33533
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
Published 2026-04-02 · Analyzed
7.1EPSS 0.005
CVE-2026-32608
Glances has a Command Injection via Process Names in Action Command Templates
Published 2026-03-18 · Analyzed
7.0EPSS 0.002
CVE-2026-35588
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
Published 2026-04-20 · Analyzed
6.3EPSS 0.002
CVE-2026-32632
Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
Published 2026-03-18 · Analyzed
5.9EPSS 0.002