his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
☆195Mar 14, 2025Updated last year
Alternatives and similar repositories for POC-CVE-2025-24813
Users that are interested in POC-CVE-2025-24813 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)☆98Apr 2, 2025Updated last year
- ☆42Mar 12, 2025Updated last year
- ☆268Jul 8, 2025Updated last year
- Unauthenticated Python PoC for CVE-2025-20281 RCE against ISE ERS API☆21Jul 28, 2025Updated last year
- PoC Exploit for the NTLM reflection SMB flaw.☆711Feb 18, 2026Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File☆405Mar 20, 2025Updated last year
- Exploit for CVE-2025-21756 for Linux kernel 6.6.75. My first linux kernel exploit!☆161Jun 5, 2025Updated last year
- Chess.com unlimited analysis (server side) for free tier!☆54May 25, 2026Updated 2 months ago
- CVE-2025-0282 is a critical vulnerability found in Ivanti Connect Secure, allowing Remote Command Execution (RCE) through a buffer overfl…☆53Jan 11, 2025Updated last year
- POC for CVE-2024-23897 Jenkins File-Read☆43Nov 20, 2025Updated 8 months ago
- CVE-2026-1731 - Critical command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access due to unsafe Bash ar…☆35Feb 11, 2026Updated 5 months ago
- This tool exploits Golden DMSA attack against delegated Managed Service Accounts.☆100Jul 15, 2025Updated last year
- CVE-2025-1974☆90Apr 2, 2025Updated last year
- Proof-of-Concept for Authorization Bypass in Next.js Middleware☆20Mar 23, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- poc for CVE-2025-14847☆26Dec 26, 2025Updated 7 months ago
- MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite☆30Feb 26, 2026Updated 5 months ago
- CVE-2025-6218 is a directory traversal vulnerability in WinRAR that allows an attacker to place files outside the intended extraction dir…☆18Jul 10, 2025Updated last year
- LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113☆521Jan 2, 2025Updated last year
- A fast WordPress plugin enumeration tool☆931Jul 9, 2026Updated 2 weeks ago
- Proof of concept & details for CVE-2025-21298☆197Jan 20, 2025Updated last year
- AD CS exploitation related stuff goes here☆25Mar 23, 2026Updated 4 months ago
- SharePoint WebPart Injection Exploit Tool☆312Nov 28, 2025Updated 8 months ago
- CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2☆142Aug 2, 2025Updated 11 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- cve-2025-24813验证脚本☆11Mar 14, 2025Updated last year
- FortiWeb CVE-2025-25257 exploit☆64Jul 11, 2025Updated last year
- CVE-2025-22457: Python Exploit POC Scanner to Detect Ivanti Connect Secure RCE☆18Apr 17, 2025Updated last year
- CVE-2025-31644: Command Injection in Appliance mode in F5 BIG-IP☆24May 11, 2025Updated last year
- HITCON 2024 x DEVCORE Wargame☆31Aug 30, 2024Updated last year
- CVE-2025-24813利用工具☆16Mar 16, 2025Updated last year
- PoC for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Iv…☆50Jan 16, 2025Updated last year
- A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnera…☆430Dec 16, 2025Updated 7 months ago
- CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)☆30Jul 11, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)☆255Dec 12, 2025Updated 7 months ago
- PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC☆317Jun 22, 2024Updated 2 years ago
- Scans WordPress sites to find unclaimed plugin slugs on the public directory.☆27Oct 12, 2025Updated 9 months ago
- CVE-2025-64155: Fortinet FortiSIEM Argument Injection to Remote Code Execution☆32Jan 13, 2026Updated 6 months ago
- ☆39Dec 14, 2024Updated last year
- CVE-2025-5777 (CitrixBleed 2) - Critical memory leak vulnerability affecting Citrix NetScaler ADC and Gateway devices☆48Jul 8, 2025Updated last year
- Apache Tomcat - Remote Code Execution via Session Deserialization (CVE-2025-24813)☆18May 25, 2025Updated last year