Sqreen operates a compact application security and runtime protection platform centered on language-specific agents for PHP and Python, with its vulnerability profile reflecting the integration challenges inherent to embedding protective instrumentation into runtime environments. The durable signal in observed disclosures centers on cryptographic signature verification and memory-safety issues, characteristic of low-level runtime instrumentation code and the boundaries between managed and native execution contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sqreen over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25489CRITICAL A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption. | Sep 17, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-25490HIGH Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual mach | Sep 17, 2020 | 7.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sqreen.
Media articles that mention a CVE ID that affects a product developed by Sqreen — matched by CVE ID, not by vendor name.