Cloudflare
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 90 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 2, 2020 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Cloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?
Resource exhaustion in quiche HTTP/3 and QPACK layers
Unbounded path event queue growth in quiche via peer-driven source connection ID rotation
Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records
Use-after-free in connection ID iterator and FFI functions
Offload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action
HTTP/2 Bomb affects Apache httpd, nginx, envoy, & pingora
Content Delivery Exploit Opens Websites to Brand Hijacking
Cache poisoning via insecure-by-default cache key
Monitor Cloudflare in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.