Cloudflare records
62 published records for vendor cloudflare.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 87.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation10
- CWE-400 Uncontrolled Resource Consumption8
- CWE-862 Missing Authorization5
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-284 Improper Access Control3
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')3
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
62 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-3907No exploit | Arbitrary filepath traversal via URI injectioncloudflare · octorpki · CWE-20 | Critical9.8 | — | 4.2% | Nov 11, 2021 |
39Monitor | CVE-2014-125026No exploit | Out-of-bounds write in github.com/cloudflare/golz4cloudflare · golz4 · CWE-787 | Critical9.8 | — | 1.1% | Dec 27, 2022 |
39Monitor | CVE-2022-3320No exploit | Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint commandcloudflare · warp · CWE-862 | Critical9.8 | — | 0.4% | Oct 28, 2022 |
37Monitor | CVE-2026-2835No exploit | HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsingcloudflare · pingora · CWE-444 | Critical9.3 | — | 0.6% | Mar 4, 2026 |
37Monitor | CVE-2026-2833No exploit | HTTP Request Smuggling via Premature Upgradecloudflare · pingora · CWE-444 | Critical9.3 | — | 0.5% | Mar 4, 2026 |
35Monitor | CVE-2022-3512No exploit | Lock WARP switch bypass using warp-cli 'add-trusted-ssid' commandcloudflare · warp · CWE-862 | High8.8 | — | 0.4% | Oct 28, 2022 |
34Monitor | CVE-2025-7054No exploit | Infinite loop triggered by connection ID retirementcloudflare · quiche · CWE-835 | High8.7 | — | 0.4% | Aug 7, 2025 |
34Monitor | CVE-2022-3337No exploit | Lock WARP switch bypass by removing VPN profile on iOS mobile clientcloudflare · warp mobile client · CWE-862 | High8.5 | — | 0.4% | Oct 28, 2022 |
33Monitor | CVE-2026-2836No exploit | Cache poisoning via insecure-by-default cache keycloudflare · pingora · CWE-345 | High8.4 | — | 0.2% | Mar 4, 2026 |
32Monitor | CVE-2022-4428No exploit | support_uri validation missing in WARP client for Windowscloudflare · warp · CWE-20 | High8.0 | — | 0.7% | Jan 11, 2023 |
32Monitor | CVE-2023-7080No exploit | Arbitrary remote code execution within wrangler dev Workers sandboxcloudflare · wrangler · CWE-269 | High8.0 | — | 0.6% | Dec 29, 2023 |
32Monitor | CVE-2023-2512No exploit | Buffer under-read in workerdcloudflare · workerd · CWE-125 | High8.1 | — | 0.6% | May 12, 2023 |
32Monitor | CVE-2023-7078No exploit | Server-Side Request Forgery (SSRF) in Miniflarecloudflare · miniflare · CWE-918 | High8.1 | — | 0.6% | Dec 29, 2023 |
32Monitor | CVE-2022-3321No exploit | Lock WARP switch feature bypass on WARP mobile client for iOScloudflare · warp mobile client · CWE-862 | High8.2 | — | 0.4% | Oct 28, 2022 |
32Monitor | CVE-2023-1732No exploit | Improper random reading in CIRCLcloudflare · circl · CWE-20 | High8.2 | — | 0.4% | May 10, 2023 |
31Monitor | CVE-2023-3036No exploit | Out of Bounds Slice index in cfnts leads to remote paniccloudflare · cfnts · CWE-119 | High7.5 | — | 2.2% | Jun 14, 2023 |
31Monitor | CVE-2025-6087No exploit | SSRF vulnerability in opennextjs-cloudflare via /_next/image endpointcloudflare · create-cloudflare · CWE-918 | High7.8 | — | 1.0% | Jun 16, 2025 |
31Monitor | CVE-2020-24356No exploit | Local Privilege Escalation in cloudflaredcloudflare · cloudflared · CWE-427 | High7.8 | — | 0.3% | Oct 2, 2020 |
31Monitor | CVE-2022-2145No exploit | Cloudlfare WARP Arbitrary File Overwritecloudflare · warp · CWE-20 | High7.8 | — | 0.3% | Jun 28, 2022 |
31Monitor | CVE-2023-0652No exploit | Local Privilege Escalation in Cloudflare WARP Installer (Windows)cloudflare · warp · CWE-59 | High7.8 | — | 0.3% | Apr 6, 2023 |
31Monitor | CVE-2020-35152No exploit | Privilege escalation through unquoted service binary path on Cloudflare WARP for Windowscloudflare · warp · CWE-428 | High7.8 | — | 0.3% | Feb 2, 2021 |
31Monitor | CVE-2022-2147No exploit | Unquoted Service Path in Cloudflare WARP for Windowscloudflare · warp · CWE-428 | High7.8 | — | 0.3% | Jun 23, 2022 |
31Monitor | CVE-2023-1314No exploit | Local Privilege Escalation Vulnerability in cloudflared's Installercloudflare · cloudflared · CWE-59 | High7.8 | — | 0.3% | Mar 21, 2023 |
31Monitor | CVE-2023-1412No exploit | Local Privilege Escalation Vulnerability in WARP's MSI Installercloudflare · warp · CWE-59 | High7.8 | — | 0.2% | Apr 5, 2023 |
31Monitor | CVE-2022-2225No exploit | Zero Trust Secure Web Gateway policies bypass using WARP client subcommandscloudflare · warp · CWE-284 | High7.8 | — | 0.2% | Jul 26, 2022 |
- CVE-2021-390740Plan
Arbitrary filepath traversal via URI injection
CriticalCVSS 9.8No exploitEPSS 4%cloudflare · octorpkiNov 11, 2021
- CVE-2014-12502639Monitor
Out-of-bounds write in github.com/cloudflare/golz4
CriticalCVSS 9.8No exploitEPSS 1%cloudflare · golz4Dec 27, 2022
- CVE-2022-332039Monitor
Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint command
CriticalCVSS 9.8No exploitEPSS 0%cloudflare · warpOct 28, 2022
- CVE-2026-283537Monitor
HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
CriticalCVSS 9.3No exploitEPSS 1%cloudflare · pingoraMar 4, 2026
- CVE-2026-283337Monitor
HTTP Request Smuggling via Premature Upgrade
CriticalCVSS 9.3No exploitEPSS 1%cloudflare · pingoraMar 4, 2026
- CVE-2022-351235Monitor
Lock WARP switch bypass using warp-cli 'add-trusted-ssid' command
HighCVSS 8.8No exploitEPSS 0%cloudflare · warpOct 28, 2022
- CVE-2025-705434Monitor
Infinite loop triggered by connection ID retirement
HighCVSS 8.7No exploitEPSS 0%cloudflare · quicheAug 7, 2025
- CVE-2022-333734Monitor
Lock WARP switch bypass by removing VPN profile on iOS mobile client
HighCVSS 8.5No exploitEPSS 0%cloudflare · warp mobile clientOct 28, 2022
- CVE-2026-283633Monitor
Cache poisoning via insecure-by-default cache key
HighCVSS 8.4No exploitEPSS 0%cloudflare · pingoraMar 4, 2026
- CVE-2022-442832Monitor
support_uri validation missing in WARP client for Windows
HighCVSS 8.0No exploitEPSS 1%cloudflare · warpJan 11, 2023
- CVE-2023-708032Monitor
Arbitrary remote code execution within wrangler dev Workers sandbox
HighCVSS 8.0No exploitEPSS 1%cloudflare · wranglerDec 29, 2023
- CVE-2023-251232Monitor
Buffer under-read in workerd
HighCVSS 8.1No exploitEPSS 1%cloudflare · workerdMay 12, 2023
- CVE-2023-707832Monitor
Server-Side Request Forgery (SSRF) in Miniflare
HighCVSS 8.1No exploitEPSS 1%cloudflare · miniflareDec 29, 2023
- CVE-2022-332132Monitor
Lock WARP switch feature bypass on WARP mobile client for iOS
HighCVSS 8.2No exploitEPSS 0%cloudflare · warp mobile clientOct 28, 2022
- CVE-2023-173232Monitor
Improper random reading in CIRCL
HighCVSS 8.2No exploitEPSS 0%cloudflare · circlMay 10, 2023
- CVE-2023-303631Monitor
Out of Bounds Slice index in cfnts leads to remote panic
HighCVSS 7.5No exploitEPSS 2%cloudflare · cfntsJun 14, 2023
- CVE-2025-608731Monitor
SSRF vulnerability in opennextjs-cloudflare via /_next/image endpoint
HighCVSS 7.8No exploitEPSS 1%cloudflare · create-cloudflareJun 16, 2025
- CVE-2020-2435631Monitor
Local Privilege Escalation in cloudflared
HighCVSS 7.8No exploitEPSS 0%cloudflare · cloudflaredOct 2, 2020
- CVE-2022-214531Monitor
Cloudlfare WARP Arbitrary File Overwrite
HighCVSS 7.8No exploitEPSS 0%cloudflare · warpJun 28, 2022
- CVE-2023-065231Monitor
Local Privilege Escalation in Cloudflare WARP Installer (Windows)
HighCVSS 7.8No exploitEPSS 0%cloudflare · warpApr 6, 2023
- CVE-2020-3515231Monitor
Privilege escalation through unquoted service binary path on Cloudflare WARP for Windows
HighCVSS 7.8No exploitEPSS 0%cloudflare · warpFeb 2, 2021
- CVE-2022-214731Monitor
Unquoted Service Path in Cloudflare WARP for Windows
HighCVSS 7.8No exploitEPSS 0%cloudflare · warpJun 23, 2022
- CVE-2023-131431Monitor
Local Privilege Escalation Vulnerability in cloudflared's Installer
HighCVSS 7.8No exploitEPSS 0%cloudflare · cloudflaredMar 21, 2023
- CVE-2023-141231Monitor
Local Privilege Escalation Vulnerability in WARP's MSI Installer
HighCVSS 7.8No exploitEPSS 0%cloudflare · warpApr 5, 2023
- CVE-2022-222531Monitor
Zero Trust Secure Web Gateway policies bypass using WARP client subcommands
HighCVSS 7.8No exploitEPSS 0%cloudflare · warpJul 26, 2022