Products: 3
    Vulnerabilities: 27
    Known Exploited: 0
    7
    Critical Level Threats
    12
    High Level Threats
    8
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-86098

    ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-86091

    ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-86090

    ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-84989

    ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags

    Last Modified: Sep 03, 2026
    Published: Sep 03, 2026

    CVE-2026-38968

    ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

    Last Modified: Jul 31, 2026
    Published: Jul 02, 2026
    Items Per Page