glances vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-68520Mediumglances: Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/configCVE-2026-68519Highglances: Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)CVE-2026-62982Highglances: Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command…CVE-2026-68517Mediumglances: Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing…CVE-2026-68518Highglances: Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstructionCVE-2026-53925Highglances: Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configurationCVE-2026-46611Mediumglances: Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding AttackCVE-2026-46608Highglances: Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)CVE-2026-46607Highglances: Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code ExecutionCVE-2026-46606Highglances: Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.pyCVE-2026-35588Mediumglances: Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config ValuesCVE-2026-35587Highglances: Glances has SSRF in IP Plugin via public_api leading to credential leakageCVE-2026-34839HighGlances: Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORSCVE-2026-33641HighGlances: Glances Vulnerable to Command Injection via Dynamic Configuration ValuesCVE-2026-33533HighGlances: Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS WildcardCVE-2026-32634HighGlances: Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed ServersCVE-2026-32633CriticalGlances: Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`CVE-2026-32632MediumGlances: Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS RebindingCVE-2026-32611HighGlances: Glances has a SQL Injection in DuckDB Export via Unparameterized DDL StatementsCVE-2026-32610HighGlances: Glances's Default CORS Configuration Allows Cross-Origin Credential TheftCVE-2026-32609HighGlances: Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP CredentialsCVE-2026-32608HighGlances: Glances has a Command Injection via Process Names in Action Command TemplatesCVE-2026-32596HighGlances: Glances exposes the REST API without authenticationCVE-2026-30930HighGlances: Glances has SQL Injection via Process Names in TimescaleDB ExportCVE-2026-30928Highglances: Glances Exposes Unauthenticated Configuration Secrets

Stop the waste.
Protect your environment with Kodem.