Exposição de Cloudflare

CDN
73
score de exposição
4.052.221
sites usam
0
em exploração
3
críticos
Análise Vexday

Com 59 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o histórico de exploração ativa do Cloudflare está abaixo da média geral do catálogo, o que sugere um perfil de risco operacional relativamente contido. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que tende a se manifestar em múltiplas classes de vulnerabilidade e merece atenção contínua no processo de revisão de código e configuração. A CVE com maior pontuação de probabilidade de exploração no momento é CVE-2021-3907, com EPSS de aproximadamente 0,04, valor baixo em termos absolutos, mas que deve ser monitorado em ambientes onde o Cloudflare atua em camadas críticas de rede ou proxy. A presença de 3 vulnerabilidades de severidade crítica e 1 CVE nova nos últimos 90 dias reforça a necessidade de manter ciclos regulares de atualização e revisão de superfície de ataque.

CVEs

63 resultados
CVE-2022-3337MEDIUMLock WARP switch bypass by removing VPN profile on iOS mobile clientEPSS 0.4%CVE-2022-3321MEDIUMLock WARP switch feature bypass on WARP mobile client for iOSEPSS 0.4%CVE-2023-1732MEDIUMImproper random reading in CIRCLEPSS 0.4%CVE-2025-59427LOWCloudflare vite plugin exposes secrets over the built-in dev serverEPSS 0.4%CVE-2020-24356MEDIUMLocal Privilege Escalation in cloudflaredEPSS 0.3%CVE-2025-0651MEDIUMFile symlink abuse might lead to deleting files belonging to SYSTEM userEPSS 0.3%CVE-2022-2145MEDIUMCloudlfare WARP Arbitrary File OverwriteEPSS 0.3%CVE-2023-0652HIGHLocal Privilege Escalation in Cloudflare WARP Installer (Windows)EPSS 0.3%CVE-2020-35152MEDIUMPrivilege escalation through unquoted service binary path on Cloudflare WARP for WindowsEPSS 0.3%CVE-2022-3322MEDIUMLock WARP switch bypass on WARP mobile client using iOS quick actionEPSS 0.3%CVE-2022-2147MEDIUMUnquoted Service Path in Cloudflare WARP for WindowsEPSS 0.3%CVE-2023-1314HIGHLocal Privilege Escalation Vulnerability in cloudflared's InstallerEPSS 0.3%CVE-2026-11941MEDIUMUse-after-free in connection ID iterator and FFI functionsEPSS 0.3%CVE-2023-1412HIGHLocal Privilege Escalation Vulnerability in WARP's MSI InstallerEPSS 0.2%CVE-2023-6992MEDIUMMemory corruption issues is Cloudflare zlib implementationEPSS 0.2%CVE-2023-0654LOWSpoofing User's Activity Loads in WARP Mobile Client (Android)EPSS 0.2%CVE-2023-0238LOWInjecting Activity Loads in WARP Mobile ClientEPSS 0.2%CVE-2026-14440HIGHCloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA recordsEPSS 0.2%CVE-2023-3747MEDIUMInsufficient Validation on Override Codes for Always-Enabled WARP ModeEPSS 0.2%CVE-2022-2225HIGHZero Trust Secure Web Gateway policies bypass using WARP client subcommandsEPSS 0.2%