Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    4
    Critical Level Threats
    4
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-33028

    In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, WinZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. NOTE: a third party has reported that this is a false positive, and has observed that the original CVE-2025-33028.md file has been deleted on GitHub. Also, this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.

    Last Modified: Apr 15, 2026
    Published: Apr 15, 2025

    CVE-2025-1240

    WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

    Last Modified: Aug 18, 2025
    Published: Feb 11, 2025

    CVE-2024-8811

    WinZip Mark-of-the-Web Bypass Vulnerability

    Last Modified: Jan 03, 2025
    Published: Nov 22, 2024

    CVE-2008-3442

    WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Last Modified: Apr 23, 2026
    Published: Aug 01, 2008

    CVE-2007-0264

    Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument. NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Last Modified: Apr 23, 2026
    Published: Jan 16, 2007
    Items Per Page
    Winzip Vulnerabilities & Security CVEs | CVE-DB