Search CVE reports


Toggle filters

1 – 10 of 22 results


CVE-2026-84990

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-83621

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-82412

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86091

Medium priority
Needs evaluation

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86090

Medium priority
Needs evaluation

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84989

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-38968

Medium priority
Needs evaluation

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result,...

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45448

Medium priority
Needs evaluation

CWE-601 URL redirection to untrusted site ('open redirect')

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-53426

Medium priority
Needs evaluation

A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

1 affected package

ntopng

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-31129

Medium priority

Some fixes available 4 of 118

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment...

11 affected packages

node-moment, wordpress, mediawiki, syncthing, omnidb...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-moment Not affected Not affected Fixed Fixed Fixed
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
syncthing Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
omnidb Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
postfixadmin Vulnerable Vulnerable Fixed Not affected Not affected
sabnzbdplus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gnucash Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ntopng Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
odoo Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
ruby-momentjs-rails Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
Show all 11 packages Show less packages