CVE-2026-21696
- EPSS 0.05%
- Veröffentlicht 19.01.2026 19:25:43
- Zuletzt bearbeitet 02.02.2026 20:40:21
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1.12.0, Wings does not consider SQLite max parameter limit when processing activity log entries allowi...
CVE-2025-69199
- EPSS 0.05%
- Veröffentlicht 19.01.2026 19:17:53
- Zuletzt bearbeitet 02.02.2026 20:41:13
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large number of co...
CVE-2025-68954
- EPSS 0.01%
- Veröffentlicht 06.01.2026 00:31:14
- Zuletzt bearbeitet 12.01.2026 21:29:12
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. Th...
CVE-2024-34066
- EPSS 0.34%
- Veröffentlicht 03.05.2024 18:15:09
- Zuletzt bearbeitet 21.02.2025 15:15:38
Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on th...
CVE-2024-34068
- EPSS 0.24%
- Veröffentlicht 03.05.2024 18:15:09
- Zuletzt bearbeitet 21.02.2025 15:19:39
Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal endpoints of...
CVE-2024-27102
- EPSS 0.44%
- Veröffentlicht 13.03.2024 21:15:59
- Zuletzt bearbeitet 23.01.2025 21:26:54
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full scope of impact ...
CVE-2023-32080
- EPSS 0.36%
- Veröffentlicht 10.05.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:02:40
Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the affected versions of Wings. This vulnerability can be used to gain access to th...
CVE-2023-25168
- EPSS 0.78%
- Veröffentlicht 09.02.2023 00:16:36
- Zuletzt bearbeitet 21.11.2024 07:49:14
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host system. In order...
CVE-2023-25152
- EPSS 0.48%
- Veröffentlicht 08.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:12
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change th...
CVE-2021-32699
- EPSS 0.05%
- Veröffentlicht 22.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:33
Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource exhaustion due to improper container process limits being defined. A mali...