CVE-2023-38831High· 7.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableRARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and al…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 19.6 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 14, 2023
Last analysed / modified upstream
98%
58 GitHub repos · Metasploit ×1
98% → 98%
Added to the CISA catalog on Aug 24, 2023. Federal remediation due Sep 14, 2023. View catalog ↗
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.
winrar < 6.23Upgrade past the affected range:
winrar 6.23Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-20250High· 7.8In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll)
CVE-2025-8088High· 8.8A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files
CVE-2022-30333High· 7.5RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file
CVE-2026-82017High· 7.6IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area
CVE-2026-49450High· 7.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2025-12999Critical· 9.1UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…