Known vulnerabilities in WinRAR

Vendor: RARLAB
Software: WinRAR
Software CPE: cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*
Total vulnerabilities: 15
Public exploits: 7
Known exploited (KEV): 4
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting WinRAR WinRAR is affected by 15 known vulnerabilities: 2 critical, 3 high, 3 medium, 7 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136808 - Heap-based Buffer Overflow
CVE-2026-14191
CWE-122 High
No
No
7.23 02.07.2026 SB2026070288
#VU136809 - Improper Link Resolution Before File Access ('Link Following')
CWE-59 Medium
No
No
7.23 02.07.2026 SB2026070288
#VU113784 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-8088
CWE-22 Critical
Available
Exploited
7.13 09.08.2025 SB2025080901
SB2025100738
SB2026080781
#VU111537 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-6218
CWE-22 High
Available
Exploited
7.11 20.06.2025 SB2025062012
#VU106931 - Product UI does not Warn User of Unsafe Actions
CVE-2025-31334
CWE-356 Medium
No
No
7.11 03.04.2025 SB2025040328
#VU92078 - Improper input validation
CVE-2024–36052
CWE-20 Low
No
No
7.00 13.06.2024 SB2024040145
SB2024061396
#VU87965 - Security Features
CVE-2024-30370
CWE-254 Medium
No
No
7.00 01.04.2024 SB2024040145
#VU79925 - Improper input validation
CVE-2023-38831
CWE-20 Critical
Available
Exploited
6.23 23.08.2023 SB2023082350
#VU79711 - Improper Validation of Array Index
CVE-2023-40477
CWE-129 High
Available
No
6.23 19.08.2023 SB2023081901
SB2023083134
SB2023083135
and 11 more
#VU71727 - Out-of-bounds read
CVE-2022-43650
CWE-125 Low
No
No
6.20 beta 3 01.02.2023 SB2023020120
#VU57604 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2021-35052
CWE-300 Low
No
No
6.10 beta 2 22.10.2021 SB2021102208
#VU17819 - Out-of-bounds write
CVE-2018-20253
CWE-787 Low
Available
No
5.70 beta 1 21.02.2019 SB2019020507
#VU17470 - Out-of-bounds write
CVE-2018-20252
CWE-787 Low
Available
No
5.70 beta 1 11.02.2019 SB2019020507
#VU17469 - Permissions, Privileges, and Access Controls
CVE-2018-20251
CWE-264 Low
Available
No
5.70 beta 1 11.02.2019 SB2019020507
#VU17468 - Permissions, Privileges, and Access Controls
CVE-2018-20250
CWE-264 Low
Available
Exploited
5.70 beta 1 11.02.2019 SB2019020507