漏洞描述 Apache Tomcat 是一个开源的 Java Servlet 容器,广泛用于运行基于 Java 的 Web 应用程序。该漏洞(CVE-2025-24813)允许远程攻击者通过特定的恶意请求在目标系统上执行任意命令,从而完全控制受影响的服务器。
相关漏洞推荐 CVE-2018-11759: Apache Tomcat JK Connect <=1.2.44 - Manager Access POC 2025-09-01 | Apache Tomcat JK Connect The Apache Web Server (httpd) specific code that normalised the requested path before matching it to... CVE-2020-1938: Ghostcat - Apache Tomcat - AJP File Read/Inclusion Vulnerability POC 2025-09-01 | Apache Tomcat When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to... tomcat-detect: Apache Tomcat Detect POC 2025-09-01 | Apache Tomcat An Apache Tomcat Manager panel was discovered. app="APACHE-Tomcat" Wordpress Plugin Depicter /wp-admin/admin-ajax.php depicter-lead-list SQL 注入漏洞(CVE-2025-2011) 无POC 2025-09-19 | Wordpress WordPress插件Depicter的滑块和弹出窗口构建器在包括3.6.1版本在内的所有版本中,由于用户提供的参数缺乏足够的转义处理和现有SQL查询的预处理不足,存在通用的SQL注入漏洞。该漏洞可以... Wordpress Plugin Eventin /wp-admin/admin-ajax.php proxy_image 文件读取漏洞(CVE-2025-3419) 无POC 2025-09-19 | Wordpress Event Manager, Events Calendar, Tickets, Registrations – Eventin 是一个用于 WordPress 的插件。该漏洞存在于其 proxy_i...