Verint records
17 published records for vendor verint.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 5.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-522 Insufficiently Protected Credentials1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2021-36450Proof of concept | Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.verint · workforce optimization · CWE-79 | Medium6.1 | — | 64.3% | Dec 15, 2021 |
39Monitor | CVE-2020-24055No exploit | Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binverint · 5620ptz firmware · CWE-787 | Critical9.8 | — | 1.6% | Aug 21, 2020 |
37Monitor | CVE-2020-24057No exploit | The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage netverint · s5120fd firmware · CWE-78 | High8.8 | — | 5.5% | Aug 21, 2020 |
36Monitor | CVE-2018-17872No exploit | Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.verint · collaboration compliance · CWE-732 | High8.8 | — | 2.2% | Oct 4, 2018 |
35Monitor | CVE-2019-12784No exploit | An issue was discovered in Verint Impact 360 15.1.verint · impact 360 · CWE-352 | High8.8 | — | 0.7% | Jul 14, 2020 |
35Monitor | CVE-2024-36396No exploit | Verint - CWE-434: Unrestricted Upload of File with Dangerous Typeverint · workforce optimization · CWE-434 | High8.8 | — | 0.4% | Jun 13, 2024 |
31Monitor | CVE-2020-12744No exploit | The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.verint · desktop and process analytics · CWE-281 | High7.8 | — | 0.2% | Oct 20, 2022 |
30Monitor | CVE-2020-24056No exploit | A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD verint · 5620ptz firmware · CWE-798 | High7.5 | — | 1.2% | Aug 21, 2020 |
27Monitor | CVE-2018-17871No exploit | Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.verint · verba collaboration compliance and quality management platform · CWE-522 | Medium6.5 | — | 1.8% | Oct 4, 2018 |
24Monitor | CVE-2019-12783No exploit | An issue was discovered in Verint Impact 360 15.1.verint · impact 360 · CWE-601 | Medium6.1 | — | 0.9% | Jul 14, 2020 |
24Monitor | CVE-2019-12773No exploit | An issue was discovered in Verint Impact 360 15.1.verint · impact 360 · CWE-79 | Medium6.1 | — | 0.8% | Jul 14, 2020 |
24Monitor | CVE-2024-36395No exploit | Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)verint · workforce optimization · CWE-80 | Medium6.1 | — | 0.3% | Jun 13, 2024 |
21Monitor | CVE-2020-23446No exploit | Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via APIverint · workforce optimization · CWE-639 | Medium5.3 | — | 1.2% | Sep 22, 2020 |
21Monitor | CVE-2021-41825No exploit | Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.verint · workforce optimization · CWE-79 | Medium5.3 | — | 1.1% | Oct 8, 2021 |
21Monitor | CVE-2020-13480No exploit | Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.verint · workforce optimization · CWE-79 | Medium5.4 | — | 1.0% | Jun 22, 2020 |
21Monitor | CVE-2023-33257No exploit | Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.verint · engagement management · CWE-79 | Medium5.4 | — | 0.4% | Aug 2, 2023 |
21Monitor | CVE-2026-21730No exploit | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism.verint · verba collaboration compliance and quality management platform · CWE-79 | Medium5.3 | — | 0.2% | May 14, 2026 |
- CVE-2021-3645043Plan
Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.
MediumCVSS 6.1Proof of conceptEPSS 64%verint · workforce optimizationDec 15, 2021
- CVE-2020-2405539Monitor
Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the bin
CriticalCVSS 9.8No exploitEPSS 2%verint · 5620ptz firmwareAug 21, 2020
- CVE-2020-2405737Monitor
The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage net
HighCVSS 8.8No exploitEPSS 5%verint · s5120fd firmwareAug 21, 2020
- CVE-2018-1787236Monitor
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.
HighCVSS 8.8No exploitEPSS 2%verint · collaboration complianceOct 4, 2018
- CVE-2019-1278435Monitor
An issue was discovered in Verint Impact 360 15.1.
HighCVSS 8.8No exploitEPSS 1%verint · impact 360Jul 14, 2020
- CVE-2024-3639635Monitor
Verint - CWE-434: Unrestricted Upload of File with Dangerous Type
HighCVSS 8.8No exploitEPSS 0%verint · workforce optimizationJun 13, 2024
- CVE-2020-1274431Monitor
The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.
HighCVSS 7.8No exploitEPSS 0%verint · desktop and process analyticsOct 20, 2022
- CVE-2020-2405630Monitor
A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD
HighCVSS 7.5No exploitEPSS 1%verint · 5620ptz firmwareAug 21, 2020
- CVE-2018-1787127Monitor
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.
MediumCVSS 6.5No exploitEPSS 2%verint · verba collaboration compliance and quality management platformOct 4, 2018
- CVE-2019-1278324Monitor
An issue was discovered in Verint Impact 360 15.1.
MediumCVSS 6.1No exploitEPSS 1%verint · impact 360Jul 14, 2020
- CVE-2019-1277324Monitor
An issue was discovered in Verint Impact 360 15.1.
MediumCVSS 6.1No exploitEPSS 1%verint · impact 360Jul 14, 2020
- CVE-2024-3639524Monitor
Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
MediumCVSS 6.1No exploitEPSS 0%verint · workforce optimizationJun 13, 2024
- CVE-2020-2344621Monitor
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
MediumCVSS 5.3No exploitEPSS 1%verint · workforce optimizationSep 22, 2020
- CVE-2021-4182521Monitor
Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.
MediumCVSS 5.3No exploitEPSS 1%verint · workforce optimizationOct 8, 2021
- CVE-2020-1348021Monitor
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
MediumCVSS 5.4No exploitEPSS 1%verint · workforce optimizationJun 22, 2020
- CVE-2023-3325721Monitor
Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.
MediumCVSS 5.4No exploitEPSS 0%verint · engagement managementAug 2, 2023
- CVE-2026-2173021Monitor
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism.
MediumCVSS 5.3No exploitEPSS 0%verint · verba collaboration compliance and quality management platformMay 14, 2026