Search CVE reports


Toggle filters

1 – 10 of 19 results


CVE-2026-86091

Medium priority
Needs evaluation

(ntopng before 6.7.260717 fails to check user privileges in the pools b ...)

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86090

Medium priority
Needs evaluation

(ntopng before 6.7.260717 fails to perform authorization checks in the ...)

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84989

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-38968

Medium priority
Needs evaluation

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result,...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45448

Medium priority
Needs evaluation

CWE-601 URL redirection to untrusted site ('open redirect')

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-53426

Medium priority
Needs evaluation

A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-31129

Medium priority

Some fixes available 4 of 118

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment...

11 affected packages

node-moment, wordpress, mediawiki, syncthing, omnidb...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-moment Not affected Not affected Fixed Fixed Fixed
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
syncthing Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
omnidb Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
postfixadmin Vulnerable Vulnerable Fixed Not affected Not affected
sabnzbdplus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gnucash Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
odoo Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
ruby-momentjs-rails Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
Show all 11 packages Show less packages

CVE-2018-12520

High priority

Some fixes available 2 of 5

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not affected Not affected Not affected Fixed
Show less packages

CVE-2017-7458

Low priority
Vulnerable

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Not affected Needs evaluation Not affected Not affected
Show less packages

CVE-2017-7459

Medium priority
Vulnerable

ntopng before 3.0 allows HTTP Response Splitting.

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Not affected Needs evaluation Not affected Not affected
Show less packages