VendorsCloudflarewarpany version
Vulnerabilities

Cloudflare WARP any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2022-3320
Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint command
Published 2022-10-28 · Modified
9.8EPSS 0.004
CVE-2022-4428
support_uri validation missing in WARP client for Windows
Published 2023-01-11 · Modified
8.9EPSS 0.007
CVE-2022-3512
Lock WARP switch bypass using warp-cli 'add-trusted-ssid' command
Published 2022-10-28 · Modified
8.8EPSS 0.004
CVE-2022-2225
Zero Trust Secure Web Gateway policies bypass using WARP client subcommands
Published 2022-07-26 · Modified
8.1EPSS 0.002
CVE-2022-2145
Cloudlfare WARP Arbitrary File Overwrite
Published 2022-06-28 · Modified
7.8EPSS 0.003
CVE-2023-0652
Local Privilege Escalation in Cloudflare WARP Installer (Windows)
Published 2023-04-06 · Modified
7.8EPSS 0.003
CVE-2020-35152
Privilege escalation through unquoted service binary path on Cloudflare WARP for Windows
Published 2021-02-02 · Modified
7.8EPSS 0.003
CVE-2022-2147
Unquoted Service Path in Cloudflare WARP for Windows
Published 2022-06-23 · Modified
7.8EPSS 0.003
CVE-2023-1412
Local Privilege Escalation Vulnerability in WARP's MSI Installer
Published 2023-04-05 · Modified
7.8EPSS 0.002
CVE-2023-2754
Plaintext transmission of DNS requests in Windows 1.1.1.1 WARP client
Published 2023-08-03 · Modified
7.4EPSS 0.009
CVE-2023-1862
Remote access to warp-svc.exe in Cloudflare WARP
Published 2023-06-20 · Modified
7.3EPSS 0.008
CVE-2025-0651
File symlink abuse might lead to deleting files belonging to SYSTEM user
Published 2025-01-22 · Analyzed
7.1EPSS 0.003
CVE-2023-0238
Injecting Activity Loads in WARP Mobile Client
Published 2023-08-29 · Modified
5.5EPSS 0.002
CVE-2022-4457
WARP client manifest misconfiguration leading to Task Hijacking
Published 2023-01-11 · Modified
5.5EPSS 0.002
CVE-2023-0654
Spoofing User's Activity Loads in WARP Mobile Client (Android)
Published 2023-08-29 · Modified
3.9EPSS 0.002