pterodactyl records
18 published records for vendor pterodactyl.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-283 Unverified Ownership1
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2026-26016No exploit | Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorizationpterodactyl · panel · CWE-283 | Critical9.2 | — | 0.5% | Feb 19, 2026 |
35Monitor | CVE-2023-32080No exploit | Wings vulnerable to escape to host from installation containerpterodactyl · wings · CWE-250 | High8.8 | — | 0.9% | May 10, 2023 |
35Monitor | CVE-2023-25152No exploit | Symbolic Link (Symlink) Following in github.com/pterodactyl/wingspterodactyl · wings · CWE-59 | High8.8 | — | 0.7% | Feb 8, 2023 |
34Monitor | CVE-2024-27102Proof of concept | Improper isolation of server file access in github.com/pterodactyl/wingspterodactyl · wings · CWE-22 | High8.5 | — | 0.6% | Mar 13, 2024 |
33Monitor | CVE-2021-41129No exploit | Authentication bypass in Pterodactylpterodactyl · panel · CWE-502 | High8.1 | — | 1.8% | Oct 6, 2021 |
33Monitor | CVE-2024-34066No exploit | Arbitrary File Write/Read in Pterodactyl wingspterodactyl · wings · CWE-552 | High8.4 | — | 0.5% | May 3, 2024 |
33Monitor | CVE-2026-21696No exploit | Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being consideredpterodactyl · wings · CWE-400 | High8.3 | — | 0.5% | Jan 19, 2026 |
33Monitor | CVE-2025-69199No exploit | Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstancespterodactyl · wings · CWE-400 | High8.3 | — | 0.3% | Jan 19, 2026 |
32Monitor | CVE-2023-25168No exploit | Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wingspterodactyl · wings · CWE-59 | High8.2 | — | 1.0% | Feb 8, 2023 |
30Monitor | CVE-2019-1020002No exploit | Pterodactyl before 0.7.14 with 2FA allows credential sniffing.pterodactyl · panel · CWE-203 | High7.5 | — | 1.5% | Jul 29, 2019 |
30Monitor | CVE-2025-68954No exploit | Pterodactyl does not revoke SFTP access when server is deleted or permissions reducedpterodactyl · panel · CWE-613 | High7.5 | — | 0.2% | Jan 5, 2026 |
26Monitor | CVE-2025-69197No exploit | Pterodactyl TOTPs can be reused during validity windowpterodactyl · panel · CWE-287 | Medium6.5 | — | 0.4% | Jan 5, 2026 |
26Monitor | CVE-2021-32699No exploit | Asymmetric Resource Consumption (Amplification) in Docker containers created by Wingspterodactyl · wings · CWE-400 | Medium6.5 | — | 0.3% | Jun 22, 2021 |
25Monitor | CVE-2024-34068No exploit | Server-side Request Forgery during remote file pull in Pterodactyl wingspterodactyl · wings · CWE-284 | Medium6.4 | — | 0.4% | May 3, 2024 |
24Monitor | CVE-2024-34067No exploit | Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panelpterodactyl · panel · CWE-79 | Medium6.1 | — | 0.5% | May 3, 2024 |
24Monitor | CVE-2025-69198No exploit | Pterodactyl's improper resource locking allows raced queries to create more resources than allotedpterodactyl · panel · CWE-400 | Medium6.0 | — | 0.2% | Jan 19, 2026 |
17Monitor | CVE-2021-41176No exploit | logout CSRF in Pterodactyl Panelpterodactyl · panel · CWE-352 | Medium4.3 | — | 0.5% | Oct 25, 2021 |
17Monitor | CVE-2021-41273No exploit | Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keyspterodactyl · panel · CWE-352 | Medium4.3 | — | 0.4% | Nov 17, 2021 |
- CVE-2026-2601636Monitor
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
CriticalCVSS 9.2No exploitEPSS 0%pterodactyl · panelFeb 19, 2026
- CVE-2023-3208035Monitor
Wings vulnerable to escape to host from installation container
HighCVSS 8.8No exploitEPSS 1%pterodactyl · wingsMay 10, 2023
- CVE-2023-2515235Monitor
Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
HighCVSS 8.8No exploitEPSS 1%pterodactyl · wingsFeb 8, 2023
- CVE-2024-2710234Monitor
Improper isolation of server file access in github.com/pterodactyl/wings
HighCVSS 8.5Proof of conceptEPSS 1%pterodactyl · wingsMar 13, 2024
- CVE-2021-4112933Monitor
Authentication bypass in Pterodactyl
HighCVSS 8.1No exploitEPSS 2%pterodactyl · panelOct 6, 2021
- CVE-2024-3406633Monitor
Arbitrary File Write/Read in Pterodactyl wings
HighCVSS 8.4No exploitEPSS 1%pterodactyl · wingsMay 3, 2024
- CVE-2026-2169633Monitor
Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered
HighCVSS 8.3No exploitEPSS 1%pterodactyl · wingsJan 19, 2026
- CVE-2025-6919933Monitor
Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances
HighCVSS 8.3No exploitEPSS 0%pterodactyl · wingsJan 19, 2026
- CVE-2023-2516832Monitor
Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wings
HighCVSS 8.2No exploitEPSS 1%pterodactyl · wingsFeb 8, 2023
- CVE-2019-102000230Monitor
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
HighCVSS 7.5No exploitEPSS 1%pterodactyl · panelJul 29, 2019
- CVE-2025-6895430Monitor
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
HighCVSS 7.5No exploitEPSS 0%pterodactyl · panelJan 5, 2026
- CVE-2025-6919726Monitor
Pterodactyl TOTPs can be reused during validity window
MediumCVSS 6.5No exploitEPSS 0%pterodactyl · panelJan 5, 2026
- CVE-2021-3269926Monitor
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
MediumCVSS 6.5No exploitEPSS 0%pterodactyl · wingsJun 22, 2021
- CVE-2024-3406825Monitor
Server-side Request Forgery during remote file pull in Pterodactyl wings
MediumCVSS 6.4No exploitEPSS 0%pterodactyl · wingsMay 3, 2024
- CVE-2024-3406724Monitor
Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel
MediumCVSS 6.1No exploitEPSS 0%pterodactyl · panelMay 3, 2024
- CVE-2025-6919824Monitor
Pterodactyl's improper resource locking allows raced queries to create more resources than alloted
MediumCVSS 6.0No exploitEPSS 0%pterodactyl · panelJan 19, 2026
- CVE-2021-4117617Monitor
logout CSRF in Pterodactyl Panel
MediumCVSS 4.3No exploitEPSS 1%pterodactyl · panelOct 25, 2021
- CVE-2021-4127317Monitor
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
MediumCVSS 4.3No exploitEPSS 0%pterodactyl · panelNov 17, 2021