Aveva Intouch Access Anywhere Path Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Active exploit activity
CVE-2022-24637Openwebanalytics Open Web Analytics privilege escalation
Public exploit or PoC available
Exploit activity linked
Potential privilege escalation to admin/root
Openwebanalytics Open Web Analytics privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2022-43671Zohocorp Manageengine Access Manager Plus SQL Injection
CVSS 9.8
New critical Zohocorp Manageengine Access Manager Plus SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.