CVE-2024-23574
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or conf
CVSS
5.3
Medium
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Published: Jul 17, 2026 · Last modified: Jul 17, 2026 · CWE-204
0.2%EPSS · 30 days0.3%
2026-08-172026-09-14
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-891735.3 MED17.9%
——5Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.4dCVE-2026-91615.3 MED9.6%
——3Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting.
This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.5dCVE-2026-867586.5 MED13.5%
——4Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.6dCVE-2026-192057.5 HIG15.8%
——5Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting.
This issue affects GastroMenum Web Panel: before 31.08.2026.7dCVE-2026-190807.5 HIG22.8%
——7Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting.
This issue affects Menulux Portal: before 20260903211448.7dCVE-2026-785844.3 MED13.3%
——4Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.12d