RARLAB Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for RARLAB products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
3
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
RARLAB KEVs Added by Year
3 RARLAB KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-6218
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability |
WinRAR | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-30333
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated... |
UnRAR | Confirmed | In CISA | 09 Aug 2022 |
|
CVE-2023-38831
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue... |
WinRAR | Confirmed | In CISA | 24 Aug 2023 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-351 — Insufficient Type Distinction 1
- CWE-59 — Improper Link Resolution Before File Access ('Link Following') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology