cleo security advisories
2 threat alerts tracking vulnerabilities and security advisories that affect cleo products.
Vulnios monitors cleo CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent cleo security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2024-55956 — cleo — harmony, lexicom
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by lever
criticalCVE-2024-55956Critical Vulnerability: CVE-2024-50623 — cleo — harmony, lexicom
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
criticalCVE-2024-50623
Track cleo exposure across your environment
Vulnios automatically cross-references your asset inventory against new cleo CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan