Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rarlab

First CVE: Dec 31, 2003Active for: 23 yearsTotal CVEs: 46
79.2
VTI Score
TOP TARGET

Rarlab maintains a focused but deeply embedded compression utility portfolio centered on WinRAR and the underlying unrar library, products whose presence in countless enterprise and consumer systems belies their narrow product count. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, have an elevated tendency toward confirmed in-the-wild exploitation and CISA KEV cataloging, and frequently acquire public exploit code, reflecting the appeal of archive-handling flaws for reliable remote code execution. The exposure recurs through a combination of memory-safety weaknesses—including out-of-bounds reads and writes, buffer over-runs, and improper bounds checking—and path-traversal conditions that arise from the parser's handling of archive entries, both classes with a long history of weaponization in the wild. Defenders should treat Rarlab advisories with urgency and prioritize patching, particularly for internet-facing or email-gateway contexts where archive processing is common; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
10.9%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Rarlab over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Apr 5, 2026
110 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-20250HIGH
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field i
Feb 5, 20197.898YESYES
CVE-2023-38831HIGH
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may inc
Aug 23, 20237.897YESYES
CVE-2022-30333HIGH
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_ke
May 9, 20227.597YESYES
CVE-2025-8088HIGH
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was ex
Aug 8, 20258.896YESNO
CVE-2025-6218HIGH
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinR
Jun 21, 20257.894YESNO
CVE-2004-1254HIGH
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer ove
Jan 10, 200510.046NOYES
CVE-2014-125119HIGH
A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File
Jul 25, 20258.442NOYES
CVE-2006-3845HIGH
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
Jul 25, 20069.338NOYES
CVE-2012-6706CRITICAL
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitra
Jun 22, 20179.835NONO
CVE-2022-43650HIGH
This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is required to exploit this vulne
Mar 29, 20237.134NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
28%
54%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local15 (32.6%)
Network16 (34.8%)
Unknown15 (32.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (60.9%)
High3 (6.5%)
Unknown15 (32.6%)
User Interaction
None13 (28.3%)
Unknown15 (32.6%)
Required17 (37.0%)
Privileges Required
Low1 (2.2%)
High1 (2.2%)
None29 (63.0%)
Unknown15 (32.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
5 CVEs
10.9% of CVEs· 100th percentile
Metasploit
4 CVEs
8.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
15.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rarlab.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rarlab — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rarlab's Products

View all 7 CNAs →

Top CWEs