pterodactyl kayıtları
pterodactyl üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-283 Unverified Ownership1
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2026-26016İstismar yok | Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorizationpterodactyl · panel · CWE-283 | Kritik9,2 | — | %0,5 | 19 Şub 2026 |
35İzleyin | CVE-2023-32080İstismar yok | Wings vulnerable to escape to host from installation containerpterodactyl · wings · CWE-250 | Yüksek8,8 | — | %0,9 | 10 May 2023 |
35İzleyin | CVE-2023-25152İstismar yok | Symbolic Link (Symlink) Following in github.com/pterodactyl/wingspterodactyl · wings · CWE-59 | Yüksek8,8 | — | %0,7 | 8 Şub 2023 |
34İzleyin | CVE-2024-27102Kavram kanıtı | Improper isolation of server file access in github.com/pterodactyl/wingspterodactyl · wings · CWE-22 | Yüksek8,5 | — | %0,6 | 13 Mar 2024 |
33İzleyin | CVE-2021-41129İstismar yok | Authentication bypass in Pterodactylpterodactyl · panel · CWE-502 | Yüksek8,1 | — | %1,8 | 6 Eki 2021 |
33İzleyin | CVE-2024-34066İstismar yok | Arbitrary File Write/Read in Pterodactyl wingspterodactyl · wings · CWE-552 | Yüksek8,4 | — | %0,5 | 3 May 2024 |
33İzleyin | CVE-2026-21696İstismar yok | Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being consideredpterodactyl · wings · CWE-400 | Yüksek8,3 | — | %0,5 | 19 Oca 2026 |
33İzleyin | CVE-2025-69199İstismar yok | Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstancespterodactyl · wings · CWE-400 | Yüksek8,3 | — | %0,3 | 19 Oca 2026 |
32İzleyin | CVE-2023-25168İstismar yok | Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wingspterodactyl · wings · CWE-59 | Yüksek8,2 | — | %1,0 | 8 Şub 2023 |
30İzleyin | CVE-2019-1020002İstismar yok | Pterodactyl before 0.7.14 with 2FA allows credential sniffing.pterodactyl · panel · CWE-203 | Yüksek7,5 | — | %1,5 | 29 Tem 2019 |
30İzleyin | CVE-2025-68954İstismar yok | Pterodactyl does not revoke SFTP access when server is deleted or permissions reducedpterodactyl · panel · CWE-613 | Yüksek7,5 | — | %0,2 | 5 Oca 2026 |
26İzleyin | CVE-2025-69197İstismar yok | Pterodactyl TOTPs can be reused during validity windowpterodactyl · panel · CWE-287 | Orta6,5 | — | %0,4 | 5 Oca 2026 |
26İzleyin | CVE-2021-32699İstismar yok | Asymmetric Resource Consumption (Amplification) in Docker containers created by Wingspterodactyl · wings · CWE-400 | Orta6,5 | — | %0,3 | 22 Haz 2021 |
25İzleyin | CVE-2024-34068İstismar yok | Server-side Request Forgery during remote file pull in Pterodactyl wingspterodactyl · wings · CWE-284 | Orta6,4 | — | %0,4 | 3 May 2024 |
24İzleyin | CVE-2024-34067İstismar yok | Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panelpterodactyl · panel · CWE-79 | Orta6,1 | — | %0,5 | 3 May 2024 |
24İzleyin | CVE-2025-69198İstismar yok | Pterodactyl's improper resource locking allows raced queries to create more resources than allotedpterodactyl · panel · CWE-400 | Orta6,0 | — | %0,2 | 19 Oca 2026 |
17İzleyin | CVE-2021-41176İstismar yok | logout CSRF in Pterodactyl Panelpterodactyl · panel · CWE-352 | Orta4,3 | — | %0,5 | 25 Eki 2021 |
17İzleyin | CVE-2021-41273İstismar yok | Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keyspterodactyl · panel · CWE-352 | Orta4,3 | — | %0,4 | 17 Kas 2021 |
- CVE-2026-2601636İzleyin
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
KritikCVSS 9,2İstismar yokEPSS %0pterodactyl · panel19 Şub 2026
- CVE-2023-3208035İzleyin
Wings vulnerable to escape to host from installation container
YüksekCVSS 8,8İstismar yokEPSS %1pterodactyl · wings10 May 2023
- CVE-2023-2515235İzleyin
Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
YüksekCVSS 8,8İstismar yokEPSS %1pterodactyl · wings8 Şub 2023
- CVE-2024-2710234İzleyin
Improper isolation of server file access in github.com/pterodactyl/wings
YüksekCVSS 8,5Kavram kanıtıEPSS %1pterodactyl · wings13 Mar 2024
- CVE-2021-4112933İzleyin
Authentication bypass in Pterodactyl
YüksekCVSS 8,1İstismar yokEPSS %2pterodactyl · panel6 Eki 2021
- CVE-2024-3406633İzleyin
Arbitrary File Write/Read in Pterodactyl wings
YüksekCVSS 8,4İstismar yokEPSS %1pterodactyl · wings3 May 2024
- CVE-2026-2169633İzleyin
Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered
YüksekCVSS 8,3İstismar yokEPSS %1pterodactyl · wings19 Oca 2026
- CVE-2025-6919933İzleyin
Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances
YüksekCVSS 8,3İstismar yokEPSS %0pterodactyl · wings19 Oca 2026
- CVE-2023-2516832İzleyin
Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wings
YüksekCVSS 8,2İstismar yokEPSS %1pterodactyl · wings8 Şub 2023
- CVE-2019-102000230İzleyin
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
YüksekCVSS 7,5İstismar yokEPSS %1pterodactyl · panel29 Tem 2019
- CVE-2025-6895430İzleyin
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
YüksekCVSS 7,5İstismar yokEPSS %0pterodactyl · panel5 Oca 2026
- CVE-2025-6919726İzleyin
Pterodactyl TOTPs can be reused during validity window
OrtaCVSS 6,5İstismar yokEPSS %0pterodactyl · panel5 Oca 2026
- CVE-2021-3269926İzleyin
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
OrtaCVSS 6,5İstismar yokEPSS %0pterodactyl · wings22 Haz 2021
- CVE-2024-3406825İzleyin
Server-side Request Forgery during remote file pull in Pterodactyl wings
OrtaCVSS 6,4İstismar yokEPSS %0pterodactyl · wings3 May 2024
- CVE-2024-3406724İzleyin
Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel
OrtaCVSS 6,1İstismar yokEPSS %0pterodactyl · panel3 May 2024
- CVE-2025-6919824İzleyin
Pterodactyl's improper resource locking allows raced queries to create more resources than alloted
OrtaCVSS 6,0İstismar yokEPSS %0pterodactyl · panel19 Oca 2026
- CVE-2021-4117617İzleyin
logout CSRF in Pterodactyl Panel
OrtaCVSS 4,3İstismar yokEPSS %1pterodactyl · panel25 Eki 2021
- CVE-2021-4127317İzleyin
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
OrtaCVSS 4,3İstismar yokEPSS %0pterodactyl · panel17 Kas 2021