tag
Eval-Injection
Critical
XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)
CVE-2025-54322·
XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment)
unpatched
Critical
safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)
CVE-2025-12735·
expr-eval npm package (mathematical/logical expression evaluator)
unpatched
Critical
pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)
CVE-2025-2945·
pgAdmin 4 (web-based PostgreSQL administration tool)
patched
Critical
Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030·
Microsoft Semantic Kernel (Python), InMemoryCollection vector store connector
patched
Critical
dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39)·
[dedoc/scramble](https://github.com/dedoc/scramble) — Laravel API documentation generator
unpatched