rarlab has 4 CVEs on record between 2019 and 2025. The median CVSS is 7.8 (high). The median gap from publication to a KEV listing is 48 days (4 cases). Most affected products: winrar (3), unrar (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 100% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- 48 d median(4)
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2025-8088High· 8.8A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files97CVE-2023-38831High· 7.8RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive93CVE-2018-20250High· 7.8In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll)92CVE-2022-30333High· 7.5RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file91
rarlab vulnerabilities
CVEs affecting rarlab, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2025-8088High· 8.8CISA KEVPoCA path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepano…
CVE-2023-38831High· 7.8CISA KEV0dayPoCRARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and al…
CVE-2022-30333High· 7.5CISA KEVPoCRARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
CVE-2018-20250High· 7.8CISA KEVPoCIn WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll)
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (ex…