Vulnerabilities (CVE)

Filtered by vendor Cloudflare Subscribe
Total 62 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-24356 1 Cloudflare 1 Cloudflared 2026-06-17 4.6 MEDIUM 6.4 MEDIUM
`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configuration files which could be abused by a malicious entity to execute commands as a privileged user. Version 2020.8.1 fixes this issue.
CVE-2014-125026 1 Cloudflare 1 Golz4 2026-06-17 N/A 9.8 CRITICAL
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.