CVE Tools

Vim

271 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Vim, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Vim CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Vim CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-012
2025-022
2025-032
2025-040
2025-050
2025-060
2025-072
2025-084
2025-090
2025-100
2025-110
2025-121
2026-010
2026-028
2026-033
2026-044
2026-054
2026-0614
2026-073
2026-0812
2026-090

Severity

How the 271 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical145%
  • High15759%
  • Medium7629%
  • Low176%

Latest CVEs

The 15 most recently published vulnerabilities affecting Vim.

  1. CVE-2026-43961Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution7.8
  2. CVE-2026-73073Vim: Arbitrary Ex Command Execution in C Omni-Completion—
  3. CVE-2026-73078Vim: Arbitrary Code Execution via Netrw Menu Construction—
  4. CVE-2026-73077Vim: Arbitrary Code Execution via Shell Keyword Lookup—
  5. CVE-2026-73076Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim`—
  6. CVE-2026-73075Vim: Out-of-bounds Access in Popup Opacity Handling—
  7. CVE-2026-73074Vim: Heap Buffer Overflow in Text Property Handling—
  8. CVE-2026-73072Vim: Heap Buffer Overflow when Loading a Spell File—
  9. CVE-2026-73071Vim: Use-after-free in JSON Decoding3.3
  10. CVE-2026-73070Vim: Stack Buffer Overflow in the Vim Socket Server5.5
  11. CVE-2026-51401An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c7.7
  12. CVE-2026-51400An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c8.4
  13. CVE-2026-59856Vim: Arbitrary Code Execution via PHP Omni-Completion7.8
  14. CVE-2026-59858Vim: Arbitrary Code Execution via C Omni-Completion7.8
  15. CVE-2026-59857Vim: Out-of-bounds Write in SAL Soundfolding5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store