Vulnerabilities in Cloudflare
61 resultsVexday analysis
Com 57 CVEs catalogadas e nenhuma registrada no CISA KEV, o histórico de vulnerabilidades da Cloudflare apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica um perfil de risco operacional relativamente contido. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), categoria que exige atenção contínua em componentes expostos a dados externos. A CVE mais perigosa no momento, CVE-2021-3907, possui EPSS de 0,04, sugerindo probabilidade de exploração ainda baixa, embora seja o ponto focal para priorização de correção. A ausência de PoCs públicas reforça o cenário atual de menor pressão imediata, mas as duas CVEs de severidade crítica devem ser monitoradas de perto dado seu potencial de impacto.
CVE-2020-24356MEDIUMLocal Privilege Escalation in cloudflaredEPSS 0.3%CVE-2025-0651MEDIUMFile symlink abuse might lead to deleting files belonging to SYSTEM userEPSS 0.3%CVE-2022-2145MEDIUMCloudlfare WARP Arbitrary File OverwriteEPSS 0.3%CVE-2026-12523HIGHResource exhaustion in quiche HTTP/3 and QPACK layersEPSS 0.3%CVE-2023-0652HIGHLocal Privilege Escalation in Cloudflare WARP Installer (Windows)EPSS 0.3%CVE-2026-12707HIGHUnbounded path event queue growth in quiche via peer-driven source connection ID rotationEPSS 0.3%CVE-2020-35152MEDIUMPrivilege escalation through unquoted service binary path on Cloudflare WARP for WindowsEPSS 0.3%CVE-2022-2147MEDIUMUnquoted Service Path in Cloudflare WARP for WindowsEPSS 0.3%CVE-2023-1314HIGHLocal Privilege Escalation Vulnerability in cloudflared's InstallerEPSS 0.3%CVE-2022-3322MEDIUMLock WARP switch bypass on WARP mobile client using iOS quick actionEPSS 0.3%CVE-2026-11941MEDIUMUse-after-free in connection ID iterator and FFI functionsEPSS 0.3%CVE-2023-1412HIGHLocal Privilege Escalation Vulnerability in WARP's MSI InstallerEPSS 0.2%CVE-2023-6992MEDIUMMemory corruption issues is Cloudflare zlib implementationEPSS 0.2%CVE-2023-0654LOWSpoofing User's Activity Loads in WARP Mobile Client (Android)EPSS 0.2%CVE-2023-0238LOWInjecting Activity Loads in WARP Mobile ClientEPSS 0.2%CVE-2026-14440HIGHCloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA recordsEPSS 0.2%CVE-2022-2225HIGHZero Trust Secure Web Gateway policies bypass using WARP client subcommandsEPSS 0.2%CVE-2023-3747MEDIUMInsufficient Validation on Override Codes for Always-Enabled WARP ModeEPSS 0.2%CVE-2022-4457MEDIUMWARP client manifest misconfiguration leading to Task HijackingEPSS 0.2%CVE-2025-13353HIGHgokey allows secret recovery from a seed file without the master passwordEPSS 0.2%