Nicolargo develops Glances, a system-monitoring and diagnostics tool with a modest but well-positioned footprint across Linux and infrastructure environments. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, driven by a recurring pattern of information-disclosure flaws, credential-handling weaknesses, and command-injection issues that arise from the tool's privileged access to system state and its exposure of sensitive metrics. Defenders should monitor this vendor's updates closely, particularly when the tool is deployed in network-monitoring or multi-user contexts; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nicolargo over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32596HIGH Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing | Mar 18, 2026 | 7.5 | 38 | NO | YES |
CVE-2026-33641HIGH Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are | Apr 2, 2026 | 7.8 | 37 | NO | YES |
CVE-2026-30928HIGH Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.c | Mar 10, 2026 | 7.5 | 36 | NO | YES |
CVE-2026-32633CRITICAL Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from | Mar 18, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-30930CRITICAL Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized sy | Mar 10, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-35587HIGH Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to i | Apr 21, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-32634HIGH Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the di | Mar 18, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-32611CRITICAL Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL o | Mar 18, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-32610HIGH Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_or | Mar 18, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-33533MEDIUM Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Con | Apr 2, 2026 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nicolargo.
Media articles that mention a CVE ID that affects a product developed by Nicolargo — matched by CVE ID, not by vendor name.