Vulnerabilities in RARLab
8 resultsVexday analysis
RARLab apresenta um perfil de risco mínimo com apenas 1 CVE registrado na base, não explorado ativamente e sem severidade crítica. A vulnerabilidade está relacionada a validação inadequada de entrada (CWE-20), mas sua antiguidade e ausência de atividade de ataque indicam baixa prioridade operacional.
CVE-2025-6218HIGHRARLAB WinRAR Directory Traversal Remote Code Execution VulnerabilityEPSS 89.4%KEVCVE-2022-43650LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interEPSS 23.0%CVE-2023-40477HIGHRARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution VulnerabilityEPSS 12.3%CVE-2014-125119HIGHWinRAR < 5.00 Filename Spoofing RCEEPSS 1.5%CVE-2025-31334MEDIUMIssue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable fileEPSS 1.2%CVE-2024-30370MEDIUMRARLAB WinRAR Mark-Of-The-Web Bypass VulnerabilityEPSS 1.2%CVE-2026-14191HIGHWinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeaderEPSS 0.9%CVE-2025-14111LOWRarlab RAR App com.rarlab.rar path traversalEPSS 0.6%