ntop
Enterprise Softwarecommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting ntop.
- CVE-2026-86098ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape7.4
- CVE-2026-86091ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler7.1
- CVE-2026-86090ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers7.1
- CVE-2026-84989ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags7.1
- CVE-2026-38968ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during ...9.8
- CVE-2026-45448ntopng - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')4.3
- CVE-2025-25066nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.8.1
- CVE-2021-36082ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.8.8
- CVE-2020-15471In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.9.1
- CVE-2020-15472In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.9.1
- CVE-2020-15473In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.9.1
- CVE-2020-15474In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.9.8
- CVE-2020-15475In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.9.8
- CVE-2020-15476In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.7.5
- CVE-2020-11940In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment...7.5