Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-38968
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cp…
Ntopng
after 6.6
HIGH 8.4
CVE-2025-25066
nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.
Ndpi
after 4.12
HIGH 8.8
CVE-2021-36082
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
Ndpi
Patch available
CRITICAL 9.8
CVE-2020-15474
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
Ndpi
after 3.2
CRITICAL 9.8
CVE-2020-15475
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
Ndpi
after 3.2
CRITICAL 9.1
CVE-2020-15471
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.
Ndpi
after 3.2
CRITICAL 9.1
CVE-2020-15473
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.
Ndpi
after 3.2
CRITICAL 9.8
CVE-2020-11939
In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in con…
Ndpi
after 3.2
HIGH 7.5
CVE-2020-11940
In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malf…
Ndpi
after 3.2
HIGH 8.1
CVE-2018-12520EPSS 11%
An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This re…
Ntopng
3.4.180617+
HIGH 7.5
CVE-2017-7458
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointe…
Ntopng
after 2.4
HIGH 7.5
CVE-2017-7459
ntopng before 3.0 allows HTTP Response Splitting.
Ntopng
after 2.4
MEDIUM 6.1
CVE-2017-7416
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
Ntopng
after 2.4
HIGH 8.8
CVE-2017-5473
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as dem…
Ntopng
after 2.4
MEDIUM 6.0
CVE-2015-8368EPSS 5%
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username param…
Ntopng
after 2.0.151021
MEDIUM 5.0
CVE-2009-2732EPSS 7%
The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference an…
Ntop
after 3.3.10