Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell operators enabled, allowing configured redirection, command chaining, or pipes to execute when an alert triggers. This issue is fixed in 4.5.6. Join the discussion | CVE Database V5 | 08/17/2026, 17:10:25 UTC Added: 08/17/2026, 17:27:20 UTC |
0 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6. Join the discussion | CVE Database V5 | 08/17/2026, 16:18:29 UTC Added: 08/17/2026, 16:41:50 UTC |
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5. Join the discussion | CVE Database V5 | 06/25/2026, 18:04:25 UTC Added: 06/25/2026, 18:31:23 UTC |
0 Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation on the target file path, piped command, or chained command. When Application Monitoring Process (AMP) modules load their command or service_cmd configuration values from glances.conf, those values are passed directly to secure_popen() with no sanitization. This allows an attacker who can modify the Glances configuration file to write arbitrary content to arbitrary filesystem paths (via >), chain arbitrary commands (via &&), or pipe command output to arbitrary programs (via |). This vulnerability is fixed in 4.5.5. Join the discussion | CVE Database V5 | 06/25/2026, 18:03:43 UTC Added: 06/25/2026, 18:31:23 UTC |
0 CVE-2026-35588 is a medium severity SQL injection vulnerability in the open-source monitoring tool Glances prior to version 4.5.4. The issue exists in the Cassandra export module where configuration values for keyspace, table, and replication_factor are directly interpolated into CQL statements without validation. This allows a user with write access to the glances.conf file to redirect monitoring data to an attacker-controlled Cassandra keyspace. Version 4.5.4 includes a fix for this vulnerability. Join the discussion | CVE Database V5 | 04/20/2026, 23:20:34 UTC Added: 04/20/2026, 23:31:07 UTC |
0 Glances versions prior to 4.5.4 have a vulnerability where the web server's REST API (/api/4/*) is accessible without authentication and allows cross-origin requests from any origin due to a permissive CORS policy. This enables malicious websites to read sensitive system information from a running Glances instance in the victim's browser, resulting in cross-origin data exfiltration. The issue was patched in version 4.5.4. Join the discussion | CVE Database V5 | 04/20/2026, 23:09:02 UTC Added: 04/20/2026, 23:31:07 UTC |
0 Glances versions prior to 4.5.3 have a permissive cross-origin resource sharing (CORS) policy in their XML-RPC server, allowing any origin to access system monitoring data. The server responds with Access-Control-Allow-Origin: * and does not validate the Content-Type header, enabling attacker-controlled webpages to send simple POST requests with XML-RPC payloads. This results in exposure of detailed system information including hostname, OS version, IP addresses, hardware stats, and full process lists with potentially sensitive command line arguments. The vulnerability is patched in version 4.5.3. Join the discussion | CVE Database V5 | 04/02/2026, 14:56:38 UTC Added: 04/02/2026, 15:08:28 UTC |
0 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system information including process command-lines containing credentials (passwords, API keys, tokens) to any network client. Version 4.5.2 fixes the issue. Join the discussion | CVE Database V5 | 03/18/2026, 05:18:11 UTC Added: 03/18/2026, 16:13:27 UTC |
Showing 1 to 8 of 8 results