Glances

Vendor:

First CVE: Mar 10, 2026 · Active for under a year

15
Total CVEs
More Total CVEs than 93% of tracked products
15.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Glances over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2026
4 months ago
Most Recent CVE
Apr 21, 2026
98 days ago

CVE Severity & Scoring

Glances15 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local3 (20.0%)
Network11 (73.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low3 (20.0%)
High1 (6.7%)
None11 (73.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing
Mar 18, 20267.538NOYES
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are
Apr 2, 20267.837NOYES
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.c
Mar 10, 20267.536NOYES
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from
Mar 18, 20269.131NONO
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized sy
Mar 10, 20269.831NONO
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to i
Apr 21, 20268.828NONO
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the di
Mar 18, 20268.127NONO
Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL o
Mar 18, 20269.127NONO
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_or
Mar 18, 20268.126NONO
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Con
Apr 2, 20266.524NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
13.3% of CVEs· 97th percentile
ExploitDB
1 CVE
6.7% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Glances

Top CWEs

Versions

No cataloged versions.