nicolargo
17 exploits
Active since Jul 2021
glances < 3.2.1 - XML External Entity Injection via Fault XML Parser
CVSS 6.3
glances < 3.2.1 - XML External Entity Injection via Fault XML Parser
CVSS 6.3
Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVSS 6.5
Glances IP Plugin has SSRF via public_api that leads to credential leakage
CVSS 8.8
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
CVSS 6.5
Glances Vulnerable to Command Injection via Dynamic Configuration Values
CVSS 7.8
Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
CVSS 9.1
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
CVSS 8.1
Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
CVSS 7.5
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
CVSS 8.1
Glances DuckDB Export - SQL Injection
CVSS 7.0
Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
CVSS 5.9
Glances <4.5.2 Action Templates - Command Injection
CVSS 7.0
Glances exposes the REST API without authentication
CVSS 7.5
Glances < 4.5.1 - Unauthenticated Sensitive Information Exposure via API Config Endpoint
CVSS 7.5
Glances < 4.5.1 - SQL Injection via TimescaleDB Export Module
CVSS 9.8
glances < 3.2.1 - XML External Entity Injection via Fault XML Parser
CVSS 6.3