Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Verifone

First CVE: Nov 15, 2012Active for: 14 yearsTotal CVEs: 11
33.1
VTI Score
Medium

Verifone develops point-of-sale terminals and payment processing systems, including flagship products such as the MX900 and VX520 and their supporting firmware and operating systems, that sit at the transaction layer of retail and hospitality environments. Its vulnerability disclosures center on memory-safety and input-handling weaknesses—buffer overflows, race conditions, command injection, and SQL injection—that are characteristic of embedded payment appliances, and a moderate tendency exists toward public exploit-code availability for these flaws. Current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Verifone over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 15, 2012
13 years ago
Most Recent CVE
Jan 28, 2026
177 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-4951HIGH
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands vi
Nov 15, 20127.534NOYES
CVE-2019-14719HIGH
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.
Oct 23, 20207.826NONO
CVE-2019-14712HIGH
Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation.
Oct 23, 20207.826NONO
CVE-2019-14717HIGH
Verifone Verix OS on VerixV Pinpad Payment Terminals with QT000530 have a Buffer Overflow via the Run system call.
Oct 23, 20207.825NONO
CVE-2019-10060HIGH
The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configurati
Mar 26, 20198.125NONO
CVE-2026-0750HIGH
Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal
Jan 28, 20267.524NONO
CVE-2019-14711HIGH
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass.
Oct 23, 20207.024NONO
CVE-2019-14718MEDIUM
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation.
Oct 23, 20206.723NONO
CVE-2019-14715MEDIUM
Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation.
Oct 23, 20206.823NONO
CVE-2019-14716MEDIUM
Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out).
Oct 23, 20206.622NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
36%
64%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (54.5%)
Network2 (18.2%)
Unknown1 (9.1%)
Physical2 (18.2%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (72.7%)
High2 (18.2%)
Unknown1 (9.1%)
User Interaction
None10 (90.9%)
Unknown1 (9.1%)
Required0 (0.0%)
Privileges Required
Low6 (54.5%)
High1 (9.1%)
None3 (27.3%)
Unknown1 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Verifone.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Verifone — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Verifone's Products

View all 3 CNAs →

Top CWEs