PoC Archive PoC Archive

tag

Eval-Injection

Critical
XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)
CVE-2025-54322· XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment) unpatched
Critical
safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)
CVE-2025-12735· expr-eval npm package (mathematical/logical expression evaluator) unpatched
Critical
pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)
CVE-2025-2945· pgAdmin 4 (web-based PostgreSQL administration tool) patched
Critical
Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030· Microsoft Semantic Kernel (Python), InMemoryCollection vector store connector patched
Critical
dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39)· [dedoc/scramble](https://github.com/dedoc/scramble) — Laravel API documentation generator unpatched