Записи Verint
17 опубликованных записей вендора verint.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 5,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-522 Insufficiently Protected Credentials1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2021-36450Proof of concept | Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.verint · workforce optimization · CWE-79 | Средняя6,1 | — | 64,3 % | 15 дек. 2021 г. |
39Наблюдать | CVE-2020-24055Эксплойта нет | Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binverint · 5620ptz firmware · CWE-787 | Критическая9,8 | — | 1,6 % | 21 авг. 2020 г. |
37Наблюдать | CVE-2020-24057Эксплойта нет | The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage netverint · s5120fd firmware · CWE-78 | Высокая8,8 | — | 5,5 % | 21 авг. 2020 г. |
36Наблюдать | CVE-2018-17872Эксплойта нет | Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.verint · collaboration compliance · CWE-732 | Высокая8,8 | — | 2,2 % | 4 окт. 2018 г. |
35Наблюдать | CVE-2019-12784Эксплойта нет | An issue was discovered in Verint Impact 360 15.1.verint · impact 360 · CWE-352 | Высокая8,8 | — | 0,7 % | 14 июл. 2020 г. |
35Наблюдать | CVE-2024-36396Эксплойта нет | Verint - CWE-434: Unrestricted Upload of File with Dangerous Typeverint · workforce optimization · CWE-434 | Высокая8,8 | — | 0,4 % | 13 июн. 2024 г. |
31Наблюдать | CVE-2020-12744Эксплойта нет | The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.verint · desktop and process analytics · CWE-281 | Высокая7,8 | — | 0,2 % | 20 окт. 2022 г. |
30Наблюдать | CVE-2020-24056Эксплойта нет | A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD verint · 5620ptz firmware · CWE-798 | Высокая7,5 | — | 1,2 % | 21 авг. 2020 г. |
27Наблюдать | CVE-2018-17871Эксплойта нет | Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.verint · verba collaboration compliance and quality management platform · CWE-522 | Средняя6,5 | — | 1,8 % | 4 окт. 2018 г. |
24Наблюдать | CVE-2019-12783Эксплойта нет | An issue was discovered in Verint Impact 360 15.1.verint · impact 360 · CWE-601 | Средняя6,1 | — | 0,9 % | 14 июл. 2020 г. |
24Наблюдать | CVE-2019-12773Эксплойта нет | An issue was discovered in Verint Impact 360 15.1.verint · impact 360 · CWE-79 | Средняя6,1 | — | 0,8 % | 14 июл. 2020 г. |
24Наблюдать | CVE-2024-36395Эксплойта нет | Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)verint · workforce optimization · CWE-80 | Средняя6,1 | — | 0,3 % | 13 июн. 2024 г. |
21Наблюдать | CVE-2020-23446Эксплойта нет | Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via APIverint · workforce optimization · CWE-639 | Средняя5,3 | — | 1,2 % | 22 сент. 2020 г. |
21Наблюдать | CVE-2021-41825Эксплойта нет | Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.verint · workforce optimization · CWE-79 | Средняя5,3 | — | 1,1 % | 8 окт. 2021 г. |
21Наблюдать | CVE-2020-13480Эксплойта нет | Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.verint · workforce optimization · CWE-79 | Средняя5,4 | — | 1,0 % | 22 июн. 2020 г. |
21Наблюдать | CVE-2023-33257Эксплойта нет | Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.verint · engagement management · CWE-79 | Средняя5,4 | — | 0,4 % | 2 авг. 2023 г. |
21Наблюдать | CVE-2026-21730Эксплойта нет | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism.verint · verba collaboration compliance and quality management platform · CWE-79 | Средняя5,3 | — | 0,2 % | 14 мая 2026 г. |
- CVE-2021-3645043В плане
Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.
СредняяCVSS 6,1Proof of conceptEPSS 64 %verint · workforce optimization15 дек. 2021 г.
- CVE-2020-2405539Наблюдать
Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the bin
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %verint · 5620ptz firmware21 авг. 2020 г.
- CVE-2020-2405737Наблюдать
The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage net
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %verint · s5120fd firmware21 авг. 2020 г.
- CVE-2018-1787236Наблюдать
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %verint · collaboration compliance4 окт. 2018 г.
- CVE-2019-1278435Наблюдать
An issue was discovered in Verint Impact 360 15.1.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %verint · impact 36014 июл. 2020 г.
- CVE-2024-3639635Наблюдать
Verint - CWE-434: Unrestricted Upload of File with Dangerous Type
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %verint · workforce optimization13 июн. 2024 г.
- CVE-2020-1274431Наблюдать
The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %verint · desktop and process analytics20 окт. 2022 г.
- CVE-2020-2405630Наблюдать
A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %verint · 5620ptz firmware21 авг. 2020 г.
- CVE-2018-1787127Наблюдать
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %verint · verba collaboration compliance and quality management platform4 окт. 2018 г.
- CVE-2019-1278324Наблюдать
An issue was discovered in Verint Impact 360 15.1.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %verint · impact 36014 июл. 2020 г.
- CVE-2019-1277324Наблюдать
An issue was discovered in Verint Impact 360 15.1.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %verint · impact 36014 июл. 2020 г.
- CVE-2024-3639524Наблюдать
Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %verint · workforce optimization13 июн. 2024 г.
- CVE-2020-2344621Наблюдать
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
СредняяCVSS 5,3Эксплойта нетEPSS 1 %verint · workforce optimization22 сент. 2020 г.
- CVE-2021-4182521Наблюдать
Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %verint · workforce optimization8 окт. 2021 г.
- CVE-2020-1348021Наблюдать
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %verint · workforce optimization22 июн. 2020 г.
- CVE-2023-3325721Наблюдать
Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %verint · engagement management2 авг. 2023 г.
- CVE-2026-2173021Наблюдать
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %verint · verba collaboration compliance and quality management platform14 мая 2026 г.