Skip to main content

Vendor archive

vim CVEs

Beta · best-effort

251 CVEs tagged to vendor vim14 Critical, 146 High, 75 Medium, 16 Low, 0 Unrated.

CVE-2026-34714

Published Mar 30, 2026

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking…

CVSS 9.2 · Critical
evidence mentions
12
Buzz score
45.6
Vendor/product tagsBeta · best-effort

CVE-2026-33412

Published Mar 24, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a…

CVSS 5.6 · Medium
evidence mentions
37
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-32249

Published Mar 12, 2026

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-28422

Published Feb 27, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fi…

CVSS 2.2 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-28421

Published Feb 27, 2026

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Bo…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-28420

Published Feb 27, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when proc…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-28419

Published Feb 27, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a ma…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-28418

Published Feb 27, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. Wh…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-28417

Published Feb 27, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By induci…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-26269

Published Feb 13, 2026

Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys comm…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-25749

Published Feb 6, 2026

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'hel…

CVSS 6.6 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-66476

Published Dec 2, 2025

Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9390

Published Aug 24, 2025

A security flaw has been discovered in vim up to 9.1.1615. Affected by this vulnerability is the function main of the file src/xxd/xxd.c of the component xxd. The manipulation res…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9389

Published Aug 24, 2025

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory co…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-55158

Published Aug 11, 2025

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55157

Published Aug 11, 2025

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during evaluation can trigger…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53906

Published Jul 15, 2025

Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening sp…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53905

Published Jul 15, 2025

Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening sp…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27423

Published Mar 3, 2025

Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starti…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26603

Published Feb 18, 2025

Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also al…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1215

Published Feb 12, 2025

A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log l…

CVSS 2.4 · Low
evidence mentions
7
Buzz score
36.8
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 26-50 of 251 CVEsPage 2 of 11