« Volver al listado

Nicolargo

Nicolargo Glances: vulnerabilidades y CVE

Nicolargo Glances tiene 15 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses15
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-35588Media (6.3)0.19%—21 abr 2026
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and…
CVE-2026-35587Alta (7.3)0.47%—21 abr 2026
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation of the public_api…
CVE-2026-34839Alta (7.7)0.47%—21 abr 2026
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests…
CVE-2026-33641Alta (7.8)0.78%—2 abr 2026
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during…
CVE-2026-33533Alta (7.1)0.47%—2 abr 2026
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP…
CVE-2026-32634Alta (8.1)0.23%—18 mar 2026
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic…
CVE-2026-32633Crítica (9.1)0.61%—18 mar 2026
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from…
CVE-2026-32632Media (5.9)0.18%—18 mar 2026
Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the MCP endpoint, but prior to version 4.5.2, the main REST/WebUI FastAPI application still accepts…
CVE-2026-32611Crítica (9.1)0.40%—18 mar 2026
Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL operations to use parameterized queries…
CVE-2026-32610Alta (8.1)0.49%—18 mar 2026
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combined with…
CVE-2026-32609Alta (7.5)0.59%—18 mar 2026
Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenticated configuration secrets exposure on the `/api/v4/config` endpoints by introducing…
CVE-2026-32608Alta (7)0.20%—18 mar 2026
Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that execute when monitoring thresholds are exceeded. These commands support…
CVE-2026-32596Alta (8.7)1.7%—18 mar 2026
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system…
CVE-2026-30930Alta (7.3)0.41%—10 mar 2026
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize()…
CVE-2026-30928Alta (8.7)1.6%—10 mar 2026
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System7
  2. T1190 Exploit Public-Facing Application6
  3. T1068 Exploitation for Privilege Escalation3
  4. T1059 Command and Scripting Interpreter2
  5. T1203 Exploitation for Client Execution2
  6. T1210 Exploitation of Remote Services2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.