Sploitus

CVE-2025-24813

100 known exploits for CVE-2025-24813

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.

Apache Tomcat
< 9.0.99, 10.1.35, 11.0.3, 10.1.0, 11.0.0
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
99.9% (100th percentile)
Weakness
CWE-502, CWE-44, CWE-706
NVD status
Analyzed
Published
2025-03-10
CVE-2025-24813 at NVD
Authoritative description, scoring and affected products

100 known exploits for CVE-2025-24813

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-POC
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-apache-tomcat
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
Tomcat-CVE_2025_24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
Apache-Tomcat---Remote-Code-Execution-via-Session-Deserialization-CVE-2025-24813-
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
lab-cve-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-PoC
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813_POC
2026-08-26 KitPloitKITPLOIT
Spring-Boot-Tomcat-CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
cve-2025-24813_poc
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-Apache-Tomcat-RCE-PoC
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-vulhub
2026-08-26 KitPloitKITPLOIT
Poc_for_CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
PutScanner
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-Scanner
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-noPoC
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
Apache-Tomcat-Vulnerability-POC-CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-PoC-exploit
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-checker
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813-PoC
2026-08-26 KitPloitKITPLOIT
Tomcat-CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
POC-CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
POC-CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-2025-24813
2026-08-26 KitPloitKITPLOIT
CVE-Arsenal-Lab
2026-08-25 KitPloitKITPLOIT
CVE-2025-24813_presentation
2026-08-25 KitPloitKITPLOIT
CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-
2026-08-25 KitPloitKITPLOIT
Apache-GOExploiter
2026-08-25 KitPloitKITPLOIT
CVE-2025-24813-Exploit
2026-08-25 KitPloitKITPLOIT
CVE-2025-24813-PoC-Apache-Tomcat-RCE
2026-08-25 KitPloitKITPLOIT
CVE-2025-24813
2026-08-25 KitPloitKITPLOIT
cve-2025-24813-poc
2026-08-25 KitPloitKITPLOIT
POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution
2026-08-24 KitPloitKITPLOIT
CVE-2025-24813-POC
2026-08-24 KitPloitKITPLOIT
CVE-2025-24813-PoC
2026-08-24 KitPloitKITPLOIT
CVE-2025-24813
2026-08-24 KitPloitKITPLOIT
Exploit for Path Equivalence in Apache Tomcat
2026-08-21 yym8538GITHUB
CVE-2025-24813-POC
2026-08-20 KitPloitKITPLOIT
Apache Tomcat 11.0.2 Remote Code Execution
2026-08-11 1dayexploitPACKETSTORMPython
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2026-07-12 yuzuki-ayanamiGITHUB
MCATester
2026-06-24 sankarayougisrivastewar-sudoGITHUB
Exploit for Use of Incorrectly-Resolved Name or Reference in Apache Tomcat
2026-06-10 DhananjayasjGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2026-03-26 EQSTLabGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-12-10 gunyakitGITHUB
đź“„ Apache Tomcat 11.0.3 Remote Session Injection
2025-11-26 indoushkaPACKETSTORMPHP
Exploit for CVE-2025-55752
2025-10-29 masahiro331GITHUB
Exploit for Path Equivalence in Apache Tomcat
2025-09-08 MakavellikGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-09-03 CEAlbezGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-08-31 drcrypterdotruGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-08-11 137fGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-08-06 cyglegitGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-07-28 ShivshantpGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-07-12 sentilaso1GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-07-03 yalemanGITHUB
Exploit for CVE-2025-2783
2025-05-26 Leviticus-TriageGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-05-11 fatkzGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-04-27 hakankarabacakGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-04-18 Erosion2020GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-04-12 Mattb709GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-04-10 FranconyuGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-04-09 f8l124GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-04-08 GadaLuBau1337GITHUB
Apache Tomcat 11.0.3 - Remote Code Execution
2025-04-07 Al Baradi JoyEXPLOITDBPython
đź“„ Apache Tomcat Remote Code Execution
2025-04-07 Al Baradi JoyPACKETSTORMPython
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-04-06 La3B0zGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-04-05 MuhammadWaseem29GITHUB
đź“„ Tomcat Partial PUT Java Deserialization
2025-04-03 sw0rd1ight, Calum Hutton, h4ck3r-04PACKETSTORMRuby
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-30 manjula-awGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-28 AlperenY-csGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-24 u238GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-24 beyond-devsecopsGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-22 tonyarrisGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-21 AlaatkGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-20 n0n-zer0GITHUB
Apache Tomcat Remote Code Execution / Information Disclosure
2025-03-18PACKETSTORM
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-18 msadeghkarimiGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-17 imbas007GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-17 imbas007GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-17 issamjrGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-16 charis3306GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-14 N0c1orGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-14 absholi7lyGITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-14 FY036GITHUB
Exploit for Deserialization of Untrusted Data in Apache Tomcat
2025-03-13 iSee857GITHUB
CVE-2025-24813
2025-03-10 apacheUNKNOWN
Tomcat Partial PUT Java Deserialization
2025-03-10 sw0rd1ight, Calum Hutton, h4ck3r-04METASPLOITRuby