Ntop maintains a focused portfolio of network traffic analysis and monitoring tools, including ndpi, ntopng, and ntop, that are deployed for deep packet inspection and visibility across enterprise and service-provider networks. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the internet-facing and privileged role these products occupy in network infrastructure. The exposure recurs through memory-safety issues—out-of-bounds reads and writes—alongside web-layer weaknesses including cross-site scripting, cross-site request forgery, and injection flaws that are characteristic of complex analysis engines with web-management interfaces. Defenders should treat this vendor's critical advisories as high-priority, particularly for internet-exposed instances or those processing untrusted network data, and monitor patch release cycles closely for the core monitoring products. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ntop over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12520HIGH An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session | Jul 5, 2018 | 8.1 | 41 | NO | YES |
CVE-2017-5473HIGH Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua | Jan 14, 2017 | 8.8 | 40 | NO | YES |
CVE-2026-38968CRITICAL ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-r | Jul 2, 2026 | 9.8 | 38 | NO | NO |
CVE-2014-5464MEDIUM Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML | Sep 8, 2014 | 4.3 | 29 | NO | YES |
CVE-2025-25066HIGH nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c. | Feb 3, 2025 | 8.4 | 26 | NO | NO |
CVE-2021-36082HIGH ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello. | Jul 1, 2021 | 8.8 | 26 | NO | NO |
CVE-2015-8368MEDIUM ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lu | Dec 17, 2015 | 6.0 | 26 | NO | YES |
CVE-2009-2732MEDIUM The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authoriz | Aug 21, 2009 | 5.0 | 26 | NO | YES |
CVE-2020-11939CRITICAL In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in concat_hash_string in ssh.c. Due t | Apr 23, 2020 | 9.8 | 25 | NO | NO |
CVE-2017-7458HIGH The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application c | Jun 26, 2017 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ntop.
Media articles that mention a CVE ID that affects a product developed by Ntop — matched by CVE ID, not by vendor name.