Verifone develops point-of-sale terminals and payment processing systems, including flagship products such as the MX900 and VX520 and their supporting firmware and operating systems, that sit at the transaction layer of retail and hospitality environments. Its vulnerability disclosures center on memory-safety and input-handling weaknesses—buffer overflows, race conditions, command injection, and SQL injection—that are characteristic of embedded payment appliances, and a moderate tendency exists toward public exploit-code availability for these flaws. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Verifone over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4951HIGH Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands vi | Nov 15, 2012 | 7.5 | 34 | NO | YES |
CVE-2019-14719HIGH Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager. | Oct 23, 2020 | 7.8 | 26 | NO | NO |
CVE-2019-14712HIGH Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation. | Oct 23, 2020 | 7.8 | 26 | NO | NO |
CVE-2019-14717HIGH Verifone Verix OS on VerixV Pinpad Payment Terminals with QT000530 have a Buffer Overflow via the Run system call. | Oct 23, 2020 | 7.8 | 25 | NO | NO |
CVE-2019-10060HIGH The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configurati | Mar 26, 2019 | 8.1 | 25 | NO | NO |
CVE-2026-0750HIGH Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal | Jan 28, 2026 | 7.5 | 24 | NO | NO |
CVE-2019-14711HIGH Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass. | Oct 23, 2020 | 7.0 | 24 | NO | NO |
CVE-2019-14718MEDIUM Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation. | Oct 23, 2020 | 6.7 | 23 | NO | NO |
CVE-2019-14715MEDIUM Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation. | Oct 23, 2020 | 6.8 | 23 | NO | NO |
CVE-2019-14716MEDIUM Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out). | Oct 23, 2020 | 6.6 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Verifone.
Media articles that mention a CVE ID that affects a product developed by Verifone — matched by CVE ID, not by vendor name.