Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Vim — Vulnerabilities & Security Advisories 49

All 49 CVE vulnerabilities found in Vim, with AI-generated Chinese analysis, references, and POCs.

This page documents the Common Vulnerabilities and Exposures associated with the vim text editor, categorized by weakness type. It serves as a centralized repository for security researchers and system administrators seeking to understand the historical and current threat landscape surrounding this widely used command-line tool. The vulnerability aggregation here collects data on memory corruption issues, buffer overflows, integer overflows, and logic errors that have been disclosed within the software. The database covers a comprehensive time range, capturing entries from the earliest tracked vulnerabilities to the most recent patches released by the vendor. This includes both security advisory announcements and independently identified flaws that impact the stability, integrity, or confidentiality of the application. By consolidating these records, the page provides a chronological view of security regression or improvement in the codebase over time. Visitors to this page can discover a detailed timeline of vulnerabilities affecting vim, allowing them to track a vendor's advisories as they are published. Users can understand a weakness class by analyzing how specific flaws, such as heap-based buffer overflows, have been exploited or mitigated in past versions. Additionally, the resource enables you to look up a product's vulnerability history, helping teams assess risk exposure and prioritize patching efforts based on the severity and age of the identified defects. This information is critical for maintaining secure configurations and ensuring that legacy versions of the editor do not remain exposed to known exploits.

Vendor: unspecified

CVE IDTitleCVSSSeverityPublished
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag CWE-78 3.6 Low2026-05-15
CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading CWE-122 6.6 Medium2026-05-08
CVE-2026-44656 Vim: OS Command Injection via 'path' completion CWE-78 7.8AIHighAI2026-05-08
CVE-2026-42307 Vim: OS Command Injection in netrw CWE-78 4.4 Medium2026-05-08
CVE-2026-41411 Vim: Command injection via backtick expansion in tag filenames CWE-78 6.6 Medium2026-04-24
CVE-2026-39881 Vim Ex command injection in Vims NetBeans integration CWE-94 5.0 Medium2026-04-08
CVE-2026-35177 Path traversal issue with zip.vim in Vim CWE-22 4.1 Medium2026-04-06
CVE-2026-34982 Vim modeline bypass via various options affects Vim < 9.2.0276 CWE-78 8.2 High2026-04-06
CVE-2026-34714 Vim 操作系统命令注入漏洞 CWE-78 9.2 Critical2026-03-30
CVE-2026-33412 Vim affected by Command injection via newline in glob() CWE-78 5.6 Medium2026-03-24
CVE-2026-32249 NFA regex engine NULL pointer dereference affects Vim < 9.2.0137 CWE-476 5.3 Medium2026-03-12
CVE-2026-28422 Vim has stack-buffer-overflow in build_stl_str_hl() CWE-121 2.2 Low2026-02-27
CVE-2026-28421 Vim has a heap-buffer-overflow and a segmentation fault CWE-20 5.3 Medium2026-02-27
CVE-2026-28420 Vim has Heap-based Buffer Overflow and OOB Read in :terminal CWE-122 4.4 Medium2026-02-27
CVE-2026-28419 Vim has Heap-based Buffer Underflow in Emacs tags parsing CWE-124 5.3 Medium2026-02-27
CVE-2026-28418 Vim has Heap-based Buffer Overflow in Emacs tags parsing CWE-122 4.4 Medium2026-02-27
CVE-2026-28417 Vim has OS Command Injection in netrw CWE-86 4.4 Medium2026-02-27
CVE-2026-26269 Vim has a Netbeans specialKeys Stack Buffer Overflow CWE-121 5.4 Medium2026-02-13
CVE-2026-25749 Heap Overflow in Vim CWE-122 6.6 Medium2026-02-06
CVE-2025-66476 Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability CWE-427 7.8 High2025-12-02
CVE-2025-9390 vim xxd xxd.c main buffer overflow CWE-120 5.3 Medium2025-08-24
CVE-2025-9389 vim memmove-vec-unaligned-erms.S __memmove_avx_unaligned_erms memory corruption CWE-119 3.3 Low2025-08-24
CVE-2025-55157 Vim heap use-after-free vulnerability when processing recursive tuple data types CWE-416 8.8AIHighAI2025-08-11
CVE-2025-55158 Vim double-free vulnerability during Vim9 script import operations CWE-415 7.8AIHighAI2025-08-11
CVE-2025-53906 Vim has path traversal issue with zip.vim and special crafted zip archives CWE-22 4.1 Medium2025-07-15
CVE-2025-53905 Vim has path traversial issue with tar.vim and special crafted tar files CWE-22 4.1 Medium2025-07-15
CVE-2025-29768 Vim vulnerable to potential data loss with zip.vim and special crafted zip files CWE-88 4.4 Medium2025-03-13
CVE-2025-27423 Improper Input Validation in Vim CWE-77 7.1 High2025-03-03
CVE-2025-26603 heap-use-after-free in function str_to_reg in vim/vim CWE-416 4.2 Medium2025-02-18
CVE-2025-1215 vim main.c memory corruption CWE-119 2.8 Low2025-02-12

All 49 known CVE vulnerabilities affecting Vim with full Chinese analysis, references, and POCs where available.