Verint develops a range of workforce optimization, analytics, and surveillance products positioned across contact centers and enterprise communications environments. Its vulnerability profile centers on web-application and command-interface weaknesses—cross-site scripting, authorization bypass, CSRF, and OS command injection—that recur across products including its Workforce Optimization suite, Impact 360 platform, and network surveillance devices such as the 4320 and 5620PTZ. A meaningful share of the vendor's disclosures reach serious severity and tend to acquire public exploit code; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Verint over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36450MEDIUM Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter. | Dec 15, 2021 | 6.1 | 70 | NO | YES |
CVE-2020-24055CRITICAL Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that liste | Aug 21, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-24057HIGH The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filtering on the unit. This endpoin | Aug 21, 2020 | 8.8 | 28 | NO | NO |
CVE-2018-17872HIGH Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions. | Oct 4, 2018 | 8.8 | 28 | NO | NO |
CVE-2024-36396HIGH Verint - CWE-434: Unrestricted Upload of File with Dangerous Type | Jun 13, 2024 | 8.8 | 27 | NO | NO |
CVE-2019-12784HIGH An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can | Jul 14, 2020 | 8.8 | 27 | NO | NO |
CVE-2026-21730MEDIUM Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incor | May 14, 2026 | 6.1 | 23 | NO | NO |
CVE-2020-24056HIGH A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW_0_42units. This could cause a | Aug 21, 2020 | 7.5 | 23 | NO | NO |
CVE-2018-17871MEDIUM Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control. | Oct 4, 2018 | 6.5 | 23 | NO | NO |
CVE-2019-12783MEDIUM An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunct | Jul 14, 2020 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Verint.
Media articles that mention a CVE ID that affects a product developed by Verint — matched by CVE ID, not by vendor name.