Записи pterodactyl
18 опубликованных записей вендора pterodactyl.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-283 Unverified Ownership1
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2026-26016Эксплойта нет | Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorizationpterodactyl · panel · CWE-283 | Критическая9,2 | — | 0,5 % | 19 февр. 2026 г. |
35Наблюдать | CVE-2023-32080Эксплойта нет | Wings vulnerable to escape to host from installation containerpterodactyl · wings · CWE-250 | Высокая8,8 | — | 0,9 % | 10 мая 2023 г. |
35Наблюдать | CVE-2023-25152Эксплойта нет | Symbolic Link (Symlink) Following in github.com/pterodactyl/wingspterodactyl · wings · CWE-59 | Высокая8,8 | — | 0,7 % | 8 февр. 2023 г. |
34Наблюдать | CVE-2024-27102Proof of concept | Improper isolation of server file access in github.com/pterodactyl/wingspterodactyl · wings · CWE-22 | Высокая8,5 | — | 0,6 % | 13 мар. 2024 г. |
33Наблюдать | CVE-2021-41129Эксплойта нет | Authentication bypass in Pterodactylpterodactyl · panel · CWE-502 | Высокая8,1 | — | 1,8 % | 6 окт. 2021 г. |
33Наблюдать | CVE-2024-34066Эксплойта нет | Arbitrary File Write/Read in Pterodactyl wingspterodactyl · wings · CWE-552 | Высокая8,4 | — | 0,5 % | 3 мая 2024 г. |
33Наблюдать | CVE-2026-21696Эксплойта нет | Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being consideredpterodactyl · wings · CWE-400 | Высокая8,3 | — | 0,5 % | 19 янв. 2026 г. |
33Наблюдать | CVE-2025-69199Эксплойта нет | Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstancespterodactyl · wings · CWE-400 | Высокая8,3 | — | 0,3 % | 19 янв. 2026 г. |
32Наблюдать | CVE-2023-25168Эксплойта нет | Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wingspterodactyl · wings · CWE-59 | Высокая8,2 | — | 1,0 % | 8 февр. 2023 г. |
30Наблюдать | CVE-2019-1020002Эксплойта нет | Pterodactyl before 0.7.14 with 2FA allows credential sniffing.pterodactyl · panel · CWE-203 | Высокая7,5 | — | 1,5 % | 29 июл. 2019 г. |
30Наблюдать | CVE-2025-68954Эксплойта нет | Pterodactyl does not revoke SFTP access when server is deleted or permissions reducedpterodactyl · panel · CWE-613 | Высокая7,5 | — | 0,2 % | 5 янв. 2026 г. |
26Наблюдать | CVE-2025-69197Эксплойта нет | Pterodactyl TOTPs can be reused during validity windowpterodactyl · panel · CWE-287 | Средняя6,5 | — | 0,4 % | 5 янв. 2026 г. |
26Наблюдать | CVE-2021-32699Эксплойта нет | Asymmetric Resource Consumption (Amplification) in Docker containers created by Wingspterodactyl · wings · CWE-400 | Средняя6,5 | — | 0,3 % | 22 июн. 2021 г. |
25Наблюдать | CVE-2024-34068Эксплойта нет | Server-side Request Forgery during remote file pull in Pterodactyl wingspterodactyl · wings · CWE-284 | Средняя6,4 | — | 0,4 % | 3 мая 2024 г. |
24Наблюдать | CVE-2024-34067Эксплойта нет | Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panelpterodactyl · panel · CWE-79 | Средняя6,1 | — | 0,5 % | 3 мая 2024 г. |
24Наблюдать | CVE-2025-69198Эксплойта нет | Pterodactyl's improper resource locking allows raced queries to create more resources than allotedpterodactyl · panel · CWE-400 | Средняя6,0 | — | 0,2 % | 19 янв. 2026 г. |
17Наблюдать | CVE-2021-41176Эксплойта нет | logout CSRF in Pterodactyl Panelpterodactyl · panel · CWE-352 | Средняя4,3 | — | 0,5 % | 25 окт. 2021 г. |
17Наблюдать | CVE-2021-41273Эксплойта нет | Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keyspterodactyl · panel · CWE-352 | Средняя4,3 | — | 0,4 % | 17 нояб. 2021 г. |
- CVE-2026-2601636Наблюдать
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %pterodactyl · panel19 февр. 2026 г.
- CVE-2023-3208035Наблюдать
Wings vulnerable to escape to host from installation container
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pterodactyl · wings10 мая 2023 г.
- CVE-2023-2515235Наблюдать
Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pterodactyl · wings8 февр. 2023 г.
- CVE-2024-2710234Наблюдать
Improper isolation of server file access in github.com/pterodactyl/wings
ВысокаяCVSS 8,5Proof of conceptEPSS 1 %pterodactyl · wings13 мар. 2024 г.
- CVE-2021-4112933Наблюдать
Authentication bypass in Pterodactyl
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %pterodactyl · panel6 окт. 2021 г.
- CVE-2024-3406633Наблюдать
Arbitrary File Write/Read in Pterodactyl wings
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %pterodactyl · wings3 мая 2024 г.
- CVE-2026-2169633Наблюдать
Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %pterodactyl · wings19 янв. 2026 г.
- CVE-2025-6919933Наблюдать
Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %pterodactyl · wings19 янв. 2026 г.
- CVE-2023-2516832Наблюдать
Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wings
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %pterodactyl · wings8 февр. 2023 г.
- CVE-2019-102000230Наблюдать
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pterodactyl · panel29 июл. 2019 г.
- CVE-2025-6895430Наблюдать
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %pterodactyl · panel5 янв. 2026 г.
- CVE-2025-6919726Наблюдать
Pterodactyl TOTPs can be reused during validity window
СредняяCVSS 6,5Эксплойта нетEPSS 0 %pterodactyl · panel5 янв. 2026 г.
- CVE-2021-3269926Наблюдать
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
СредняяCVSS 6,5Эксплойта нетEPSS 0 %pterodactyl · wings22 июн. 2021 г.
- CVE-2024-3406825Наблюдать
Server-side Request Forgery during remote file pull in Pterodactyl wings
СредняяCVSS 6,4Эксплойта нетEPSS 0 %pterodactyl · wings3 мая 2024 г.
- CVE-2024-3406724Наблюдать
Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel
СредняяCVSS 6,1Эксплойта нетEPSS 0 %pterodactyl · panel3 мая 2024 г.
- CVE-2025-6919824Наблюдать
Pterodactyl's improper resource locking allows raced queries to create more resources than alloted
СредняяCVSS 6,0Эксплойта нетEPSS 0 %pterodactyl · panel19 янв. 2026 г.
- CVE-2021-4117617Наблюдать
logout CSRF in Pterodactyl Panel
СредняяCVSS 4,3Эксплойта нетEPSS 1 %pterodactyl · panel25 окт. 2021 г.
- CVE-2021-4127317Наблюдать
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
СредняяCVSS 4,3Эксплойта нетEPSS 0 %pterodactyl · panel17 нояб. 2021 г.