İçeriğe atla
Noroxi

pterodactyl kayıtları

pterodactyl üreticisine ait 18 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

18 kayıt
  • CVE-2026-26016
    36İzleyin

    Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization

    KritikCVSS 9,2İstismar yokEPSS %0

    pterodactyl · panel19 Şub 2026

  • CVE-2023-32080
    35İzleyin

    Wings vulnerable to escape to host from installation container

    YüksekCVSS 8,8İstismar yokEPSS %1

    pterodactyl · wings10 May 2023

  • CVE-2023-25152
    35İzleyin

    Symbolic Link (Symlink) Following in github.com/pterodactyl/wings

    YüksekCVSS 8,8İstismar yokEPSS %1

    pterodactyl · wings8 Şub 2023

  • CVE-2024-27102
    34İzleyin

    Improper isolation of server file access in github.com/pterodactyl/wings

    YüksekCVSS 8,5Kavram kanıtıEPSS %1

    pterodactyl · wings13 Mar 2024

  • CVE-2021-41129
    33İzleyin

    Authentication bypass in Pterodactyl

    YüksekCVSS 8,1İstismar yokEPSS %2

    pterodactyl · panel6 Eki 2021

  • CVE-2024-34066
    33İzleyin

    Arbitrary File Write/Read in Pterodactyl wings

    YüksekCVSS 8,4İstismar yokEPSS %1

    pterodactyl · wings3 May 2024

  • CVE-2026-21696
    33İzleyin

    Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered

    YüksekCVSS 8,3İstismar yokEPSS %1

    pterodactyl · wings19 Oca 2026

  • CVE-2025-69199
    33İzleyin

    Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances

    YüksekCVSS 8,3İstismar yokEPSS %0

    pterodactyl · wings19 Oca 2026

  • CVE-2023-25168
    32İzleyin

    Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wings

    YüksekCVSS 8,2İstismar yokEPSS %1

    pterodactyl · wings8 Şub 2023

  • Pterodactyl before 0.7.14 with 2FA allows credential sniffing.

    YüksekCVSS 7,5İstismar yokEPSS %1

    pterodactyl · panel29 Tem 2019

  • CVE-2025-68954
    30İzleyin

    Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced

    YüksekCVSS 7,5İstismar yokEPSS %0

    pterodactyl · panel5 Oca 2026

  • CVE-2025-69197
    26İzleyin

    Pterodactyl TOTPs can be reused during validity window

    OrtaCVSS 6,5İstismar yokEPSS %0

    pterodactyl · panel5 Oca 2026

  • CVE-2021-32699
    26İzleyin

    Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings

    OrtaCVSS 6,5İstismar yokEPSS %0

    pterodactyl · wings22 Haz 2021

  • CVE-2024-34068
    25İzleyin

    Server-side Request Forgery during remote file pull in Pterodactyl wings

    OrtaCVSS 6,4İstismar yokEPSS %0

    pterodactyl · wings3 May 2024

  • CVE-2024-34067
    24İzleyin

    Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel

    OrtaCVSS 6,1İstismar yokEPSS %0

    pterodactyl · panel3 May 2024

  • CVE-2025-69198
    24İzleyin

    Pterodactyl's improper resource locking allows raced queries to create more resources than alloted

    OrtaCVSS 6,0İstismar yokEPSS %0

    pterodactyl · panel19 Oca 2026

  • CVE-2021-41176
    17İzleyin

    logout CSRF in Pterodactyl Panel

    OrtaCVSS 4,3İstismar yokEPSS %1

    pterodactyl · panel25 Eki 2021

  • CVE-2021-41273
    17İzleyin

    Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys

    OrtaCVSS 4,3İstismar yokEPSS %0

    pterodactyl · panel17 Kas 2021