Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nicolargo — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting nicolargo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Nicolargo is primarily known for developing security tools and open-source projects, with a core focus on system administration and network security. The project has historically been associated with vulnerabilities including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. Security assessments reveal that misconfigurations and input validation issues have been recurring concerns. While no major public security incidents have been widely documented, the 15 CVEs on record highlight persistent security challenges in its codebase, particularly around improper access controls and insecure default settings. The project's security posture reflects common issues in open-source development, emphasizing the need for rigorous testing and secure coding practices.

Top products by nicolargo: glances
CVE ID Title CVSS Severity Published
CVE-2026-68519 Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925) — glances CWE-78 7.1 High 2026-08-17
CVE-2026-62982 Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection — glances CWE-78 8.8 High 2026-08-17
CVE-2026-68520 Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config — glances CWE-200 5.3 Medium 2026-08-17
CVE-2026-68517 Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard — glances CWE-942 6.5 Medium 2026-08-17
CVE-2026-68518 Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction — glances CWE-78 8.8 High 2026-08-17
CVE-2026-46608 Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533) — glances CWE-183 7.4 High 2026-06-25
CVE-2026-46607 Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution — glances CWE-502 7.8 High 2026-06-25
CVE-2026-53925 Glances: Arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration — glances CWE-22 7.8 High 2026-06-25
CVE-2026-46606 Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py — glances CWE-78 7.8 High 2026-06-25
CVE-2026-46611 Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack — glances CWE-346 5.3 Medium 2026-06-25
CVE-2026-35588 Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values — glances CWE-89 6.3 Medium 2026-04-20
CVE-2026-35587 Glances IP Plugin has SSRF via public_api that leads to credential leakage — glances CWE-918 9.8AI Critical AI 2026-04-20
CVE-2026-34839 Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS — glances CWE-200 6.5AI Medium AI 2026-04-20
CVE-2026-33641 Glances Vulnerable to Command Injection via Dynamic Configuration Values — glances CWE-78 7.8 High 2026-04-02
CVE-2026-33533 Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard — glances CWE-942 8.1AI High AI 2026-04-02
CVE-2026-32634 Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers — glances CWE-346 8.1 High 2026-03-18
CVE-2026-32633 Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist` — glances CWE-200 9.1 Critical 2026-03-18
CVE-2026-32632 Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding — glances CWE-346 5.9 Medium 2026-03-18
CVE-2026-32611 Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements — glances CWE-89 7.0 High 2026-03-18
CVE-2026-32610 Glances's Default CORS Configuration Allows Cross-Origin Credential Theft — glances CWE-942 8.1 High 2026-03-18
CVE-2026-32609 Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials — glances CWE-200 7.5 High 2026-03-18
CVE-2026-32608 Glances has a Command Injection via Process Names in Action Command Templates — glances CWE-78 7.0 High 2026-03-18
CVE-2026-32596 Glances exposes the REST API without authentication — glances CWE-200 9.1 - 2026-03-18
CVE-2026-30930 Glances has SQL Injection via Process Names in TimescaleDB Export — glances CWE-89 9.8AI Critical AI 2026-03-10
CVE-2026-30928 Glances Exposes Unauthenticated Configuration Secrets — glances CWE-200 9.1AI Critical AI 2026-03-10

This page lists every published CVE security advisory associated with nicolargo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.