Nov 11, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Aveva Intouch Access Anywhere: public exploit or PoC linked (Path Traversal)
  • 3 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2022-23854 Aveva Intouch Access Anywhere Path Traversal

  • Public exploit or PoC available
  • Exploit activity linked

Aveva Intouch Access Anywhere Path Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2022-24637 Openwebanalytics Open Web Analytics privilege escalation

  • Public exploit or PoC available
  • Exploit activity linked
  • Potential privilege escalation to admin/root

Openwebanalytics Open Web Analytics privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-43671 Zohocorp Manageengine Access Manager Plus SQL Injection

  • CVSS 9.8

New critical Zohocorp Manageengine Access Manager Plus SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-23854 Exploit

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated u...

CVE-2022-37197 Exploit

IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.

CVE-2022-37661 Exploit

SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.

CVE-2022-32429 Exploit

An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch...

CVE-2022-31188 Exploit

CVAT is an opensource interactive video and image annotation tool for computer vision.

CVE-2022-24637 Exploit

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used t...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-43671 CVSS 9.8

Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.

CVE-2022-43672 CVSS 9.8

Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a di...

CVE-2022-45182 CVSS 9.8

Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.

View critical disclosures

cvelogic Threat Intelligence