Vulnerabilities
10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-0750 | Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5. NVD description · AI analysis pending | 8.7 | <1% | PoC |
| — | |
| CVE-2019-14719 | Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager. Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2019-14712 | Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation. Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2019-14715 | Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation. Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation. NVD description · AI analysis pending | 6.8 | <1% |
| — | ||
| CVE-2019-10060 | The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code vi The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allows attackers to execute arbitrary code via a long configuration key value. An attacker must be able to download files to the device in order to exploit this vulnerability. NVD description · AI analysis pending | 8.1 | 2% |
| — |