CVE-2026-44656
- EPSS 0.92%
- Veröffentlicht 08.05.2026 22:40:49
- Zuletzt bearbeitet 24.07.2026 20:10:00
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are execut...
CVE-2026-42307
- EPSS 0.77%
- Veröffentlicht 08.05.2026 22:38:53
- Zuletzt bearbeitet 24.07.2026 21:10:00
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// proto...
CVE-2026-41411
- EPSS 0.5%
- Veröffentlicht 24.04.2026 16:51:39
- Zuletzt bearbeitet 27.04.2026 13:39:23
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve env...
CVE-2026-39881
- EPSS 0.62%
- Veröffentlicht 08.04.2026 20:18:19
- Zuletzt bearbeitet 24.07.2026 21:10:00
Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in ...
CVE-2026-35177
- EPSS 0.13%
- Veröffentlicht 06.04.2026 17:54:42
- Zuletzt bearbeitet 24.07.2026 21:10:00
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. ...
CVE-2026-34982
- EPSS 0.47%
- Veröffentlicht 06.04.2026 15:16:48
- Zuletzt bearbeitet 15.07.2026 02:20:36
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing...
CVE-2026-34714
- EPSS 0.59%
- Veröffentlicht 30.03.2026 18:27:55
- Zuletzt bearbeitet 15.07.2026 02:20:33
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
CVE-2026-33412
- EPSS 0.83%
- Veröffentlicht 24.03.2026 19:43:07
- Zuletzt bearbeitet 15.07.2026 02:20:12
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may b...
CVE-2026-32249
- EPSS 0.13%
- Veröffentlicht 12.03.2026 19:17:23
- Zuletzt bearbeitet 23.07.2026 13:39:50
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits th...
CVE-2026-28419
- EPSS 0.17%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 21:22:05
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim...