Skip to content
Noroxi

pterodactyl records

18 published records for vendor pterodactyl.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

18 records
  • Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization

    CriticalCVSS 9.2No exploitEPSS 0%

    pterodactyl · panelFeb 19, 2026

  • Wings vulnerable to escape to host from installation container

    HighCVSS 8.8No exploitEPSS 1%

    pterodactyl · wingsMay 10, 2023

  • Symbolic Link (Symlink) Following in github.com/pterodactyl/wings

    HighCVSS 8.8No exploitEPSS 1%

    pterodactyl · wingsFeb 8, 2023

  • Improper isolation of server file access in github.com/pterodactyl/wings

    HighCVSS 8.5Proof of conceptEPSS 1%

    pterodactyl · wingsMar 13, 2024

  • Authentication bypass in Pterodactyl

    HighCVSS 8.1No exploitEPSS 2%

    pterodactyl · panelOct 6, 2021

  • Arbitrary File Write/Read in Pterodactyl wings

    HighCVSS 8.4No exploitEPSS 1%

    pterodactyl · wingsMay 3, 2024

  • Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered

    HighCVSS 8.3No exploitEPSS 1%

    pterodactyl · wingsJan 19, 2026

  • Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances

    HighCVSS 8.3No exploitEPSS 0%

    pterodactyl · wingsJan 19, 2026

  • Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wings

    HighCVSS 8.2No exploitEPSS 1%

    pterodactyl · wingsFeb 8, 2023

  • Pterodactyl before 0.7.14 with 2FA allows credential sniffing.

    HighCVSS 7.5No exploitEPSS 1%

    pterodactyl · panelJul 29, 2019

  • Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced

    HighCVSS 7.5No exploitEPSS 0%

    pterodactyl · panelJan 5, 2026

  • Pterodactyl TOTPs can be reused during validity window

    MediumCVSS 6.5No exploitEPSS 0%

    pterodactyl · panelJan 5, 2026

  • Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings

    MediumCVSS 6.5No exploitEPSS 0%

    pterodactyl · wingsJun 22, 2021

  • Server-side Request Forgery during remote file pull in Pterodactyl wings

    MediumCVSS 6.4No exploitEPSS 0%

    pterodactyl · wingsMay 3, 2024

  • Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel

    MediumCVSS 6.1No exploitEPSS 0%

    pterodactyl · panelMay 3, 2024

  • Pterodactyl's improper resource locking allows raced queries to create more resources than alloted

    MediumCVSS 6.0No exploitEPSS 0%

    pterodactyl · panelJan 19, 2026

  • logout CSRF in Pterodactyl Panel

    MediumCVSS 4.3No exploitEPSS 1%

    pterodactyl · panelOct 25, 2021

  • Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys

    MediumCVSS 4.3No exploitEPSS 0%

    pterodactyl · panelNov 17, 2021