Products: 4
    Vulnerabilities: 6
    Known Exploited: 2
    3
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-84115

    Cleo Harmony JWT Refresh Token connections privileges management

    Last Modified: Sep 01, 2026
    Published: Sep 01, 2026

    CVE-2026-84114

    Cleo Harmony SAML Authentication LocalUserUtil.getNativeUserByAssertions improper authentication

    Last Modified: Sep 01, 2026
    Published: Sep 01, 2026

    CVE-2024-55956

    In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

    Last Modified: Nov 04, 2025
    Published: Dec 13, 2024

    CVE-2024-50623

    In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

    Last Modified: Nov 05, 2025
    Published: Oct 27, 2024

    CVE-2021-33577

    An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves (via encryption and signing of the message) can be bypassed by changing the Content-Type of the message to text/plain.

    Last Modified: Nov 21, 2024
    Published: Jun 18, 2021
    Items Per Page
    Cleo Vulnerabilities & Security CVEs | CVE-DB