CVE-2026-82578
- EPSS 0.41%
- Veröffentlicht 11.09.2026 14:22:29
- Zuletzt bearbeitet 18.09.2026 19:40:31
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.
CVE-2026-78224
- EPSS 0.44%
- Veröffentlicht 11.09.2026 14:20:06
- Zuletzt bearbeitet 18.09.2026 19:40:31
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
CVE-2026-82583
- EPSS 0.45%
- Veröffentlicht 11.09.2026 14:17:24
- Zuletzt bearbeitet 18.09.2026 19:40:31
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and ...
CVE-2023-43208
- EPSS 82.71%
- Veröffentlicht 26.10.2023 17:15:09
- Zuletzt bearbeitet 31.10.2025 14:39:17
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
CVE-2023-37679
- EPSS 99.43%
- Veröffentlicht 03.08.2023 03:15:10
- Zuletzt bearbeitet 09.07.2026 01:18:30
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.