cleo has 3 CVEs on record between 2022 and 2024. The median CVSS is 9.8 (critical), with 2 rated critical. Most affected products: harmony (2), cleo (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 67% vs 1% corpus
- Median CVSS
- 9.8
- Publish → KEV
- —(2)
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2024-55956Critical· 9.8In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…100CVE-2024-50623Critical· 9.8In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.100CVE-2022-42966Medium· 5.9cleo is vulnerable to Regular Expression Denial of Service (ReDoS)33
cleo vulnerabilities
CVEs affecting cleo, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2024-55956Critical· 9.8CISA KEVPoCIn Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…
CVE-2024-50623Critical· 9.8CISA KEVPoCIn Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVE-2022-42966Medium· 5.9cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
cleo is vulnerable to Regular Expression Denial of Service (ReDoS)