Ntop

Ntopng

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 21.09.2026 16:09:20
  • Zuletzt bearbeitet 29.09.2026 16:17:12

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any authenticated ...

  • EPSS 0.29%
  • Veröffentlicht 21.09.2026 16:08:23
  • Zuletzt bearbeitet 23.09.2026 17:17:50

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for ...

  • EPSS 0.35%
  • Veröffentlicht 21.09.2026 15:56:26
  • Zuletzt bearbeitet 23.09.2026 17:17:49

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports param...

Medienbericht
  • EPSS 0.29%
  • Veröffentlicht 04.09.2026 21:48:47
  • Zuletzt bearbeitet 23.09.2026 17:17:46

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irrev...

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 04.09.2026 21:48:46
  • Zuletzt bearbeitet 23.09.2026 17:17:46

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and rec...

  • EPSS 0.22%
  • Veröffentlicht 03.09.2026 14:47:01
  • Zuletzt bearbeitet 09.09.2026 21:09:13

ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag.lua` — perfo...

  • EPSS 0.38%
  • Veröffentlicht 02.07.2026 00:00:00
  • Zuletzt bearbeitet 08.07.2026 18:39:19

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated lo...

  • EPSS 0.17%
  • Veröffentlicht 14.05.2026 16:48:18
  • Zuletzt bearbeitet 14.05.2026 18:24:08

CWE-601 URL redirection to untrusted site ('open redirect')

  • EPSS 0.29%
  • Veröffentlicht 21.11.2024 14:15:18
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

Exploit
  • EPSS 10.68%
  • Veröffentlicht 05.07.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:45:21

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An attacker with forekno...