CVE-2024-23574Medium· 5.3▾ SunlitHCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force tec…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61503Medium· 5.3Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences
CVE-2025-34255Medium· 5.3D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is…
CVE-2026-86778Medium· 5.3Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc
CVE-2026-102587Low· 2.7A flaw was found in Moodle
CVE-2025-66307Medium· 6.5This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages
CVE-2025-62181Medium· 5.3Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration