pkg:PyPI/glances
17 total CVEsCRITICAL2HIGH9MEDIUM6
✅ Check your installed version
All known vulnerabilities
- from 0, < 4.5.1
- CRITICAL9.1CVE-2026-32633Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`from 0, < 4.5.2
- from 0, < 4.5.4
- HIGH8.1CVE-2026-32634Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Serversfrom 0, < 4.5.2
- from 0, < 4.5.2
- from 0, < 4.5.3
- HIGH7.5CVE-2026-32609Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentialsfrom 0, < 4.5.2
- from 0, < 4.5.2
- from 0, < 4.5.1
- HIGH7.0CVE-2026-32611Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statementsfrom 0, < 4.5.2
- from 0, < 4.5.2
- MEDIUM6.5CVE-2026-34839Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORSfrom 0, < 4.5.4
- MEDIUM6.5CVE-2026-33533Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcardfrom 0, < 4.5.3
- MEDIUM6.3CVE-2026-35588Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Valuesfrom 0, < 4.5.4
- from 0, < 85d5a6b4af31fcf785d5a61086cbbd166b40b07a, < 9d6051be4a42f692392049fdbfc85d5dfa458b32, < 4b87e979afdc06d98ed1b48da31e69eaa3a9fb94 | from 0, < 3.2.1
- from 0, < 3.2.1
- MEDIUM5.9CVE-2026-32632Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebindingfrom 0, < 4.5.2