RARLAB vendor intelligence

RARLAB Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting RARLAB products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse RARLAB KEVs Full KEV feed
Total KEVs
3
Known exploited vulnerabilities affecting RARLAB products
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
RARLAB KEVs with sensor-observed exploitation activity

The catalog gap matters for RARLAB exposure

All three exploited RARLAB CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.

100%
Covered by CISA
0%
Beyond CISA
2
Product families

Attested RARLAB CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-6218

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability

WinRAR Confirmed In CISA 01 Jun 2026
CVE-2022-30333

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated...

UnRAR Confirmed In CISA 09 Aug 2022
CVE-2023-38831

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue...

WinRAR Confirmed In CISA 24 Aug 2023

Showing 3 of 3 RARLAB known exploited vulnerabilities.

Recurring weakness patterns

Limitation, insufficient type distinction, and link resolution before file access ('link following') account for four mapped occurrences across this RARLAB KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.