Man's vulnerability footprint concentrates in a modestly represented data-visualization and analytics tool (D-Tale) that exhibits a pronounced skew toward critical-severity outcomes. The recurring weakness classes—cross-site scripting, code injection, and server-side request forgery—reflect the product's web-facing architecture and code-generation features, while public exploit code has frequently emerged for disclosed flaws. Defenders should treat updates to this vendor's tooling as urgent when deployed in multi-user or internet-exposed contexts; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Man over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3408CRITICAL man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded | Jun 6, 2024 | 9.8 | 85 | NO | YES |
CVE-2026-35052CRITICAL D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or | Apr 6, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-27194CRITICAL D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale p | Feb 21, 2026 | 9.8 | 31 | NO | NO |
CVE-2023-46134CRITICAL D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to version 3.7.0, users hosting D-Tale publicly can be vulnerabl | Oct 25, 2023 | 9.8 | 26 | NO | NO |
CVE-2024-45595CRITICAL D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. | Sep 10, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-21642HIGH D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers | Jan 5, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Man.
Media articles that mention a CVE ID that affects a product developed by Man — matched by CVE ID, not by vendor name.