ZeroHour

Vulnerabilities

17 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21730
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism.

Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization, an attacker can inject a malicious XSS payload into the username field. This payload will be executed in the context of the administrator’s browser when the admin accesses the web application's log viewer. The vendor was notified early about this vulnerability, but didn't respond to our messages. This issue was fixed in version 10.0.6

NVD description · AI analysis pending
5.3<1%
  • verint verba collaboration compliance and quality management platform
CVE-2024-36396
+1 in the same advisory: …36395
Verint - CWE-434: Unrestricted Upload of File with Dangerous Type

Verint - CWE-434: Unrestricted Upload of File with Dangerous Type

NVD description · AI analysis pending
8.8
group max
<1%
  • verint workforce optimization
CVE-2023-33257
Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.

Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.

NVD description · AI analysis pending
5.4<1% PoC
  • verint engagement management
CVE-2020-12744
The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.

The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.

NVD description · AI analysis pending
7.8<1%
  • verint desktop and process analytics
CVE-2021-36450
Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.

Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.

NVD description · AI analysis pending
6.164% PoC
  • verint workforce optimization
CVE-2021-41825
Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.

Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.

NVD description · AI analysis pending
5.31% PoC
  • verint workforce optimization
CVE-2020-23446
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API

Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API

NVD description · AI analysis pending
5.31% PoC ×2
  • verint workforce optimization
CVE-2020-24057
The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filtering on th

The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filtering on the unit. This endpoint is vulnerable to a command injection. An authenticated attacker can leverage this issue to execute arbitrary commands as 'root'.

NVD description · AI analysis pending
8.85% PoC
  • verint s5120fd firmware
CVE-2020-24055
+1 in the same advisory: …24056
Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr

Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that this service does not require any authentication.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • verint 5620ptz firmware
  • verint 4320 firmware
CVE-2019-12784
+2 in the same advisory: …12783 …12773
An issue was discovered in Verint Impact 360 15.1.

An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them to guess and potentially compromise valid credentials without ever sending any traffic from their own machine to the target site.

NVD description · AI analysis pending
8.8
group max
<1%
  • verint impact 360
CVE-2020-13480
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.

Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.

NVD description · AI analysis pending
5.4<1% PoC ×3
  • verint workforce optimization
CVE-2018-17872
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.

Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.

NVD description · AI analysis pending
8.82% PoC ×3
  • verint collaboration compliance
  • verint quality management platform
CVE-2018-17871
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.

Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.

NVD description · AI analysis pending
6.52% PoC ×3
  • verint verba collaboration compliance and quality management platform