Ntop
3 CVEs tracked since 2014. Since Jun 2014, none of them reached CISA KEV.
Ntop CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2014-06 | 2 | 0 |
| 2014-07 | null or fewer | |
| 2014-08 | null or fewer | |
| 2014-09 | null or fewer | |
| 2014-10 | null or fewer | |
| 2014-11 | null or fewer | |
| 2014-12 | null or fewer | |
| 2015-01 | null or fewer | |
| 2015-02 | null or fewer | |
| 2015-03 | null or fewer | |
| 2015-04 | null or fewer | |
| 2015-05 | null or fewer | |
| 2015-06 | null or fewer | |
| 2015-07 | null or fewer | |
| 2015-08 | null or fewer | |
| 2015-09 | null or fewer | |
| 2015-10 | null or fewer | |
| 2015-11 | null or fewer | |
| 2015-12 | 1 | 0 |
Products
The products that kept showing up in Ntop's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Ntop.
- CVE-2026-84990ntopng: Missing Authorization on System Configuration Backup Download and Listing8.8
- CVE-2026-83621ntopng: Missing Authorization Check in REST API Allows Non-Admin Users to Tamper Threat Intelligence Blacklist URLs8.1
- CVE-2026-82412ntopng: Remote Code Execution via OS Command Injection in Vulnerability-Scan REST API8.8
- CVE-2026-86098ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape7.4
- CVE-2026-86091ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler7.1
- CVE-2026-86090ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers7.1
- CVE-2026-84989ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags7.1
- CVE-2026-38968ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during ...9.8
- CVE-2026-45448ntopng - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')4.3
- CVE-2025-25066nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.8.1
- CVE-2021-36082ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.8.8
- CVE-2020-15471In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.9.1
- CVE-2020-15472In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.9.1
- CVE-2020-15473In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.9.1
- CVE-2020-15474In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.9.8
The record
- Peak rank
- #64 in Jun 2014
- Busiest month shown
- Jun 2014, 2 CVEs
- Months with a KEV entry
- 0 since Jun 2014
- Monthly snapshots
- 2 since 2014