Skip to main content

Vendor/product archive

ntop / ntopng CVEs

Beta · best-effort

9 CVEs tagged to ntop / ntopng1 Critical, 4 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-38968

Published Jul 2, 2026

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2018-12520

Published Jul 5, 2018

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7458

Published Jun 26, 2017

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7416

Published Jun 26, 2017

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5473

Published Jan 14, 2017

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8368

Published Dec 17, 2015

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.l…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5464

Published Sep 8, 2014

Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4329

Published Jun 19, 2014

Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1