Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nicolargo

First CVE: Mar 10, 2026Active for: 1 yearTotal CVEs: 15
61.5
VTI Score
TOP TARGET

Nicolargo develops Glances, a system-monitoring and diagnostics tool with a modest but well-positioned footprint across Linux and infrastructure environments. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, driven by a recurring pattern of information-disclosure flaws, credential-handling weaknesses, and command-injection issues that arise from the tool's privileged access to system state and its exposure of sensitive metrics. Defenders should monitor this vendor's updates closely, particularly when the tool is deployed in network-monitoring or multi-user contexts; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
15.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nicolargo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2026
4 months ago
Most Recent CVE
Apr 21, 2026
94 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-32596HIGH
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing
Mar 18, 20267.538NOYES
CVE-2026-33641HIGH
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are
Apr 2, 20267.837NOYES
CVE-2026-30928HIGH
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.c
Mar 10, 20267.536NOYES
CVE-2026-32633CRITICAL
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from
Mar 18, 20269.131NONO
CVE-2026-30930CRITICAL
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized sy
Mar 10, 20269.831NONO
CVE-2026-35587HIGH
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to i
Apr 21, 20268.828NONO
CVE-2026-32634HIGH
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the di
Mar 18, 20268.127NONO
CVE-2026-32611CRITICAL
Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL o
Mar 18, 20269.127NONO
CVE-2026-32610HIGH
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_or
Mar 18, 20268.126NONO
CVE-2026-33533MEDIUM
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Con
Apr 2, 20266.524NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
27%
53%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (20.0%)
Network11 (73.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low3 (20.0%)
High1 (6.7%)
None11 (73.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
13.3% of CVEs· 97th percentile
ExploitDB
1 CVE
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nicolargo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nicolargo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nicolargo's Products

View all 1 CNAs →

Top CWEs