CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2024-50623

KEV · ransomware Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
Listed
ransomware
Class
other
CWE-434, CWE-434, CWE-434

Description

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

References

Status: profiled · ingested 2026-07-31T06:00:00.000Z