Логотип exploitDog
bind:CVE-2026-30930
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-30930

Количество 4

Количество 4

ubuntu логотип

CVE-2026-30930

20 дней назад

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() method wraps string values in single quotes but does not escape embedded single quotes, making SQL injection trivial via attacker-controlled data such as process names, filesystem mount points, network interface names, or container names. This vulnerability is fixed in 4.5.1.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-30930

20 дней назад

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() method wraps string values in single quotes but does not escape embedded single quotes, making SQL injection trivial via attacker-controlled data such as process names, filesystem mount points, network interface names, or container names. This vulnerability is fixed in 4.5.1.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-30930

20 дней назад

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-x46r-mf5g-xpr6

20 дней назад

Glances has SQL Injection via Process Names in TimescaleDB Export

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-30930

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() method wraps string values in single quotes but does not escape embedded single quotes, making SQL injection trivial via attacker-controlled data such as process names, filesystem mount points, network interface names, or container names. This vulnerability is fixed in 4.5.1.

CVSS3: 9.8
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-30930

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() method wraps string values in single quotes but does not escape embedded single quotes, making SQL injection trivial via attacker-controlled data such as process names, filesystem mount points, network interface names, or container names. This vulnerability is fixed in 4.5.1.

CVSS3: 9.8
0%
Низкий
20 дней назад
debian логотип
CVE-2026-30930

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 9.8
0%
Низкий
20 дней назад
github логотип
GHSA-x46r-mf5g-xpr6

Glances has SQL Injection via Process Names in TimescaleDB Export

0%
Низкий
20 дней назад

Уязвимостей на страницу