VulnSea

ntop has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.8 (high). None have a confirmed exploitation report. The most common weakness class is CWE-862 (4). Most affected products: ntopng (5), nDPI (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
6 prev 0

Products

  • ntopng 5
  • nDPI 1
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ntop vulnerabilities

CVEs affecting ntop, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-83621High· 8.1
yesterday

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.…

Twilightntop · ntopngvia NVD
CVE-2026-84990High· 8.8
yesterday

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any a…

Twilightntop · ntopngvia NVD
CVE-2026-82412High· 8.8
yesterday

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the sca…

Twilightntop · ntopngvia NVD
CVE-2026-86098High· 7.4
2w ago

ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries

ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network pack…

Twilightntop · nDPIEPSS 0.35%via NVD
CVE-2026-86090High· 7.1
2w ago

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endp…

Twilightntop · ntopngEPSS 0.25%via NVD
CVE-2026-86091High· 7.1PoC
2w ago

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endp…

Midnightntop · ntopngEPSS 0.29%via NVD
ntop vulnerabilities (CVEs) · VulnSea