Glances
Vendor:
First CVE: Mar 10, 2026 · Active for under a year
15
Total CVEs
More Total CVEs than 93% of tracked products
15.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Glances over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2026
4 months ago
Most Recent CVE
Apr 21, 2026
98 days ago
CVE Severity & Scoring
Glances15 CVEs
27%
53%
20%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (20.0%)
Network11 (73.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low3 (20.0%)
High1 (6.7%)
None11 (73.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32596HIGH Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing | Mar 18, 2026 | 7.5 | 38 | NO | YES |
CVE-2026-33641HIGH Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are | Apr 2, 2026 | 7.8 | 37 | NO | YES |
CVE-2026-30928HIGH Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.c | Mar 10, 2026 | 7.5 | 36 | NO | YES |
CVE-2026-32633CRITICAL Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from | Mar 18, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-30930CRITICAL Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized sy | Mar 10, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-35587HIGH Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to i | Apr 21, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-32634HIGH Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the di | Mar 18, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-32611CRITICAL Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL o | Mar 18, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-32610HIGH Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_or | Mar 18, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-33533MEDIUM Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Con | Apr 2, 2026 | 6.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
13.3% of CVEs· 97th percentile
ExploitDB
1 CVE
6.7% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Glances
Top CWEs
Versions
No cataloged versions.