Cloudflare, Inc.

First CVE: Oct 2, 2020Active for: 6 years
69
CVEs Published
More CVEs Published than 65% of tracked CNAs
9.9
Avg CVEs / Year
More Avg CVEs / Year than 54% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 59% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Cloudflare, Inc. as a CNA, 91.3% affect products that Cloudflare, Inc. develops as a vendor.

91.3%
Self-reported: 63Third-party: 6

Of all the CVEs published that affect products developed by Cloudflare, Inc., 98.4% are self-published by Cloudflare, Inc. as a CNA.

98.4%
Self-published: 63Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by Cloudflare, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 2, 2020
5 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by Cloudflare, Inc. as a CNA, regardless of affected vendor or product.

69 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This au
Jul 1, 20266.835NONO
Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3
Jul 14, 20267.532NONO
The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. E
Feb 24, 20269.832NONO
An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1
Mar 5, 20269.131NONO
An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing
Mar 5, 20269.131NONO
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed d
Jan 20, 20269.931NONO
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint
Oct 28, 20229.831NONO
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche s
Jul 14, 20267.530NONO
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.
May 13, 20259.830NONO
A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementat
Mar 5, 20268.128NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA69 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local15 (21.7%)
Network48 (69.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network6 (8.7%)
Attack Complexity
Low63 (91.3%)
High6 (8.7%)
Unknown0 (0.0%)
User Interaction
None55 (79.7%)
Unknown0 (0.0%)
Required13 (18.8%)
Privileges Required
Low19 (27.5%)
High0 (0.0%)
None50 (72.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (69 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Cloudflare, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Cloudflare, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs