Glance Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-63770

    Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass

    Last Modified: Aug 21, 2026
    Published: Jul 20, 2026

    CVE-2022-25937

    Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).

    Last Modified: Mar 21, 2025
    Published: Feb 13, 2023

    CVE-2022-31546

    The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Last Modified: Nov 21, 2024
    Published: Jul 11, 2022

    CVE-2018-3748

    There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in <a> element) allows to execute JavaScript code against any user who opens a directory listing containing such crafted file name.

    Last Modified: Nov 21, 2024
    Published: Jul 03, 2018

    CVE-2018-3715

    glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.

    Last Modified: Nov 21, 2024
    Published: Jun 07, 2018
    Items Per Page
    Glance_Project Vulnerabilities & Security CVEs | CVE-DB