CVE-2026-102454High· 7.2▾ TwilightEasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102455Critical· 9.8EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability
CVE-2026-102457Medium· 6.5EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability
CVE-2026-102458Critical· 9.8EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability
CVE-2026-102459Medium· 6.1EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability
CVE-2026-102456Medium· 6.5EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability
CVE-2024-50623Critical· 9.8In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.