RARLAB Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for RARLAB products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

3

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

RARLAB KEVs Added by Year

Loading...

3 RARLAB KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-6218

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2022-30333

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated...

Confirmed In CISA 09 Aug 2022
CVE-2023-38831

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue...

Confirmed In CISA 24 Aug 2023

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-351 — Insufficient Type Distinction 1
  • CWE-59 — Improper Link Resolution Before File Access ('Link Following') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology