CVE Tools

Ntop

3 CVEs tracked since 2014. Since Jun 2014, none of them reached CISA KEV.

Ntop CVEs per month

Jun 2014 to Dec 2015. Point at a month, or focus the strip and use the arrow keys.
Ntop CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-0620
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-1210

Products

The products that kept showing up in Ntop's monthly top three, with their CVEs summed over those months.

  1. Ntopng22 months
  2. Ntop11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Ntop.

  1. CVE-2026-84990ntopng: Missing Authorization on System Configuration Backup Download and Listing8.8
  2. CVE-2026-83621ntopng: Missing Authorization Check in REST API Allows Non-Admin Users to Tamper Threat Intelligence Blacklist URLs8.1
  3. CVE-2026-82412ntopng: Remote Code Execution via OS Command Injection in Vulnerability-Scan REST API8.8
  4. CVE-2026-86098ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape7.4
  5. CVE-2026-86091ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler7.1
  6. CVE-2026-86090ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers7.1
  7. CVE-2026-84989ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags7.1
  8. CVE-2026-38968ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during ...9.8
  9. CVE-2026-45448ntopng - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')4.3
  10. CVE-2025-25066nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.8.1
  11. CVE-2021-36082ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.8.8
  12. CVE-2020-15471In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.9.1
  13. CVE-2020-15472In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.9.1
  14. CVE-2020-15473In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.9.1
  15. CVE-2020-15474In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.9.8

The record

Peak rank
#64 in Jun 2014
Busiest month shown
Jun 2014, 2 CVEs
Months with a KEV entry
0 since Jun 2014
Monthly snapshots
2 since 2014
Ntop's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store