VYPR
Vendor

Verifone

Products
12
CVEs
11
Across products
22
Status
Private

Products

12

Recent CVEs

11
  • CVE-2019-10060HigMar 26, 2019
    risk 0.53cvss 8.1epss 0.02

    The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this…

  • CVE-2019-14719HigOct 23, 2020
    risk 0.51cvss 7.8epss 0.01

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.

  • CVE-2019-14717HigOct 23, 2020
    risk 0.51cvss 7.8epss 0.00

    Verifone Verix OS on VerixV Pinpad Payment Terminals with QT000530 have a Buffer Overflow via the Run system call.

  • CVE-2019-14712HigOct 23, 2020
    risk 0.51cvss 7.8epss 0.00

    Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation.

  • CVE-2026-0750HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5.

  • CVE-2019-14711HigOct 23, 2020
    risk 0.46cvss 7.0epss 0.00

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass.

  • CVE-2019-14718MedOct 23, 2020
    risk 0.44cvss 6.7epss 0.01

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation.

  • CVE-2019-14715MedOct 23, 2020
    risk 0.44cvss 6.8epss 0.00

    Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation.

  • CVE-2019-14716MedOct 23, 2020
    risk 0.43cvss 6.6epss 0.00

    Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out).

  • CVE-2019-14713MedOct 23, 2020
    risk 0.36cvss 5.5epss 0.00

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages.

  • CVE-2012-4951Nov 15, 2012
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.