Man

D-tale

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 21.02.2026 04:25:38
  • Zuletzt bearbeitet 23.02.2026 20:47:29

D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers ...

  • EPSS 0.21%
  • Veröffentlicht 20.03.2025 10:09:34
  • Zuletzt bearbeitet 15.04.2025 16:15:47

Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45595. Notes: All CVE users should reference CVE-2024-45595 instead of this CVE Record. All references and descriptions in this candidate ...

  • EPSS 3.72%
  • Veröffentlicht 13.12.2024 18:15:22
  • Zuletzt bearbeitet 13.12.2024 18:15:22

D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where ...

  • EPSS 1.64%
  • Veröffentlicht 10.09.2024 16:15:21
  • Zuletzt bearbeitet 20.09.2024 19:59:02

D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input...

Exploit
  • EPSS 91.71%
  • Veröffentlicht 06.06.2024 19:16:01
  • Zuletzt bearbeitet 21.11.2024 09:29:32

man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge ...

  • EPSS 0.41%
  • Veröffentlicht 05.01.2024 22:15:43
  • Zuletzt bearbeitet 21.11.2024 08:54:47

D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0,...

  • EPSS 2.13%
  • Veröffentlicht 25.10.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:27:57

D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to version 3.7.0, users hosting D-Tale publicly can be vulnerable to remote code execution, allowing attackers to run malicious code o...