Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 21 Oct 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 20 Dec 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cleo harmony
|
|
| CPEs | cpe:2.3:a:cleo:harmony:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cleo harmony
|
Tue, 17 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Sat, 14 Dec 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Fri, 13 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 10 Dec 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Tue, 10 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 |
Fri, 15 Nov 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.8.0.20, there is a JavaScript Injection vulnerability: unrestricted file upload and download could lead to remote code execution. | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. |
Wed, 30 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cleo
Cleo harmomy Cleo lexicom Cleo vltrader |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:cleo:harmomy:*:*:*:*:*:*:*:* cpe:2.3:a:cleo:lexicom:*:*:*:*:*:*:*:* cpe:2.3:a:cleo:vltrader:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cleo
Cleo harmomy Cleo lexicom Cleo vltrader |
|
| Metrics |
cvssV3_1
|
Mon, 28 Oct 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.8.0.20, there is a JavaScript Injection vulnerability. | In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.8.0.20, there is a JavaScript Injection vulnerability: unrestricted file upload and download could lead to remote code execution. |
Sun, 27 Oct 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.8.0.20, there is a JavaScript Injection vulnerability. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-21T22:55:37.946Z
Reserved: 2024-10-27T00:00:00.000Z
Link: CVE-2024-50623
Updated: 2024-10-30T20:12:26.927Z
Status : Analyzed
Published: 2024-10-28T00:15:03.657
Modified: 2025-11-05T18:17:58.247
Link: CVE-2024-50623
No data.
OpenCVE Enrichment
No data.