Vim
This hub aggregates every CVE we track for Vim, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
259
CVEs tracked
14
Critical
154
High
0
In CISA KEV
Severity distribution
HIGH154MEDIUM75LOW16CRITICAL14
Monthly trend
1
1
0
0
2
2
2
0
0
0
2
4
0
0
0
1
0
8
3
4
4
14
3
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Vim.
- CVE-2026-59856Vim: Arbitrary Code Execution via PHP Omni-Completion7.8
- CVE-2026-59858Vim: Arbitrary Code Execution via C Omni-Completion7.8
- CVE-2026-59857Vim: Out-of-bounds Write in SAL Soundfolding5.5
- CVE-2026-55693Vim: Out-of-bounds Write in Spell File Word Count7.8
- CVE-2026-55892Vim: Out-of-bounds Write in Spell File Prefix Dump5.5
- CVE-2026-55895Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename7.8
- CVE-2026-57451Vim: Out-of-bounds Read in Text Property Count5.3
- CVE-2026-57452Vim: Out-of-bounds Read with libsodium-encrypted Files5.5
- CVE-2026-57453Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction6.5
- CVE-2026-57454Vim: Out-of-bounds Read with Text Properties6.1
- CVE-2026-57455Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument7.8
- CVE-2026-57456Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings7.8
- CVE-2026-52860Vim: Arbitrary Code Execution via Python Omni-Completion7.8
- CVE-2026-52859Vim: Out-of-bounds Read in Terminal Screen Snapshot8.2
- CVE-2026-52858Vim: Arbitrary Code Execution via Python Omni-Completion7.8
Product normalization is registry-driven with AI assist and human review. How it works