CVE-2026-27194
- EPSS 0.38%
- Veröffentlicht 21.02.2026 04:25:38
- Zuletzt bearbeitet 23.02.2026 20:47:29
D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers ...
CVE-2024-9016
- EPSS 0.21%
- Veröffentlicht 20.03.2025 10:09:34
- Zuletzt bearbeitet 15.04.2025 16:15:47
Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45595. Notes: All CVE users should reference CVE-2024-45595 instead of this CVE Record. All references and descriptions in this candidate ...
CVE-2024-55890
- EPSS 3.72%
- Veröffentlicht 13.12.2024 18:15:22
- Zuletzt bearbeitet 13.12.2024 18:15:22
D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where ...
CVE-2024-45595
- EPSS 1.64%
- Veröffentlicht 10.09.2024 16:15:21
- Zuletzt bearbeitet 20.09.2024 19:59:02
D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input...
CVE-2024-3408
- EPSS 91.71%
- Veröffentlicht 06.06.2024 19:16:01
- Zuletzt bearbeitet 21.11.2024 09:29:32
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge ...
CVE-2024-21642
- EPSS 0.41%
- Veröffentlicht 05.01.2024 22:15:43
- Zuletzt bearbeitet 21.11.2024 08:54:47
D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0,...
CVE-2023-46134
- EPSS 2.13%
- Veröffentlicht 25.10.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:27:57
D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to version 3.7.0, users hosting D-Tale publicly can be vulnerable to remote code execution, allowing attackers to run malicious code o...