Vulnerabilities in RARLAB
8 resultsVexday analysis
A RARLAB apresenta um perfil de risco moderado com 6 vulnerabilidades conhecidas, sendo 1 atualmente explorada em ataques ativos (KEV). Nenhuma das falhas foi classificada como crítica, mas a fraqueza dominante (CWE-129 - Improper Validation of Array Index) indica problemas de validação que podem levar a comportamentos inesperados. O cenário é estável, com apenas 1 vulnerabilidade publicada nos últimos 90 dias.
CVE-2025-6218HIGHRARLAB WinRAR Directory Traversal Remote Code Execution VulnerabilityEPSS 89.4%KEVCVE-2022-43650LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interEPSS 23.0%CVE-2023-40477HIGHRARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution VulnerabilityEPSS 12.3%CVE-2014-125119HIGHWinRAR < 5.00 Filename Spoofing RCEEPSS 1.5%CVE-2025-31334MEDIUMIssue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable fileEPSS 1.2%CVE-2024-30370MEDIUMRARLAB WinRAR Mark-Of-The-Web Bypass VulnerabilityEPSS 1.2%CVE-2026-14191HIGHWinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeaderEPSS 0.9%CVE-2025-14111LOWRarlab RAR App com.rarlab.rar path traversalEPSS 0.6%