nicolargo
15 exploits
Active since Jul 2021
Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVSS 6.5
Glances IP Plugin has SSRF via public_api that leads to credential leakage
CVSS 8.8
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
CVSS 6.5
Glances Vulnerable to Command Injection via Dynamic Configuration Values
CVSS 7.8
Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
CVSS 9.1
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
CVSS 8.1
Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
CVSS 7.5
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
CVSS 8.1
Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
CVSS 7.0
Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
CVSS 5.9
Glances has a Command Injection via Process Names in Action Command Templates
CVSS 7.0
Glances exposes the REST API without authentication
CVSS 7.5
Glances <4.5.1 - Info Disclosure
CVSS 7.5
Glances <4.5.1 - SQL Injection
CVSS 9.8
Glances < 3.2.1 - XXE
CVSS 6.3