Vim Security Vulnerabilities (CVEs)

Track 64 security vulnerabilities affecting Vim products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

2 Critical
52 High
10 Medium
🔔 Get Alerts for Vim
CVE-2026-26269 5.4

A stack buffer overflow vulnerability in Vim's NetBeans integration allows remote code execution when processing malicious specialKeys commands. This ...

Feb 13, 2026
CVE-2026-25749 6.6

A heap buffer overflow vulnerability in Vim's tag file resolution logic allows attackers to execute arbitrary code or crash the application by exploit...

Feb 6, 2026
CVE-2025-66476 7.8

This CVE describes an uncontrolled search path vulnerability in Vim on Windows that allows arbitrary code execution. When Vim runs external commands v...

Dec 2, 2025
CVE-2025-9390 5.3

A buffer overflow vulnerability in vim's xxd component allows local attackers to execute arbitrary code or cause denial of service. The flaw exists in...

Aug 24, 2025
CVE-2025-55157 8.8

This CVE describes a use-after-free vulnerability in Vim's tuple reference management when processing nested tuples in Vim script. An attacker could e...

Aug 11, 2025
CVE-2025-53905 4.1

A path traversal vulnerability in Vim's tar.vim plugin allows specially crafted tar archives to overwrite arbitrary files when opened. This affects Vi...

Jul 15, 2025
CVE-2025-29768 4.4

Vim versions before 9.1.1198 contain a vulnerability in zip.vim that could cause data loss when users view specially crafted zip files and press 'x' o...

Mar 13, 2025
CVE-2025-27423 7.1

This vulnerability in Vim's tar.vim plugin allows arbitrary shell command execution when opening specially crafted tar archives. Attackers can exploit...

Mar 3, 2025
CVE-2025-22134 4.2

CVE-2025-22134 is a heap-buffer overflow vulnerability in Vim that occurs when switching buffers using the :all command while visual mode is active. T...

Jan 13, 2025
CVE-2024-45306 4.5

A heap buffer overflow vulnerability in Vim text editor occurs when cursor position becomes invalid and points beyond line boundaries, potentially cau...

Sep 2, 2024
CVE-2024-43374 4.5

CVE-2024-43374 is a use-after-free vulnerability in Vim's argument list handling that can cause the editor to crash. It affects users running Vim vers...

Aug 16, 2024
CVE-2024-41965 4.2

This CVE describes a double-free vulnerability in Vim's dialog_changed() function that occurs when abandoning an unnamed modified buffer. The vulnerab...

Aug 1, 2024
CVE-2024-22667 7.8

CVE-2024-22667 is a stack-based buffer overflow vulnerability in Vim's map.c file where the did_set_langmap function uses sprintf to write to an error...

Feb 5, 2024
CVE-2023-5344 7.5

CVE-2023-5344 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 9.0.1969. Attackers can exploit this by tricking user...

Oct 2, 2023
CVE-2023-4750 7.8

CVE-2023-4750 is a use-after-free vulnerability in Vim text editor that could allow an attacker to execute arbitrary code by tricking a user into open...

Sep 4, 2023
CVE-2023-4751 7.8

CVE-2023-4751 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 9.0.1331. Attackers can exploit this by tricking user...

Sep 3, 2023
CVE-2023-4736 7.8

CVE-2023-4736 is an untrusted search path vulnerability in Vim that allows attackers to execute arbitrary code by placing malicious files in directori...

Sep 2, 2023
CVE-2023-4734 7.8

An integer overflow vulnerability in Vim before version 9.0.1846 allows attackers to cause a denial of service or potentially execute arbitrary code b...

Sep 2, 2023
CVE-2023-3896 7.8

This vulnerability is a divide-by-zero error in Vim text editor versions 9.0.1367-1 through 9.0.1367-3. It allows attackers to crash Vim by opening sp...

Aug 7, 2023
CVE-2020-20703 9.8

A buffer overflow vulnerability in VIM versions 8.1.2135 allows remote attackers to execute arbitrary code by exploiting the operand parameter. This a...

Jun 20, 2023
CVE-2023-1127 7.8

CVE-2023-1127 is a divide-by-zero vulnerability in Vim text editor that can cause a crash or potentially allow arbitrary code execution when processin...

Mar 1, 2023
CVE-2022-2598 6.5

CVE-2022-2598 is an out-of-bounds write vulnerability in Vim's API that could allow arbitrary code execution when processing specially crafted input. ...

Aug 1, 2022
CVE-2022-2522 7.8

CVE-2022-2522 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 9.0.0061. Attackers can exploit this by tricking user...

Jul 25, 2022
CVE-2022-2345 7.8

This CVE describes a Use After Free vulnerability in Vim text editor versions prior to 9.0.0046. Attackers can exploit this memory corruption flaw by ...

Jul 8, 2022
CVE-2022-2210 7.8

CVE-2022-2210 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

Jun 27, 2022
CVE-2022-2207 7.8

CVE-2022-2207 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Jun 27, 2022
CVE-2022-2206 7.8

CVE-2022-2206 is an out-of-bounds read vulnerability in Vim text editor versions prior to 8.2. This allows attackers to read sensitive memory contents...

Jun 26, 2022
CVE-2022-2182 7.8

CVE-2022-2182 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Jun 23, 2022
CVE-2022-2175 7.8

CVE-2022-2175 is a buffer over-read vulnerability in Vim text editor versions prior to 8.2. This allows attackers to read memory beyond allocated buff...

Jun 23, 2022
CVE-2022-2129 7.8

CVE-2022-2129 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

Jun 19, 2022
CVE-2022-2125 7.8

CVE-2022-2125 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Jun 19, 2022
CVE-2022-2124 7.8

CVE-2022-2124 is a buffer over-read vulnerability in Vim text editor that allows reading beyond allocated memory boundaries. This affects users runnin...

Jun 19, 2022
CVE-2022-2042 7.8

CVE-2022-2042 is a use-after-free vulnerability in Vim text editor versions prior to 8.2. This memory corruption flaw could allow attackers to execute...

Jun 10, 2022
CVE-2022-2000 7.8

CVE-2022-2000 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

Jun 9, 2022
CVE-2022-1968 7.8

CVE-2022-1968 is a use-after-free vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tricking ...

Jun 2, 2022
CVE-2022-1897 7.8

CVE-2022-1897 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

May 27, 2022
CVE-2022-1898 7.8

CVE-2022-1898 is a use-after-free vulnerability in Vim text editor that allows attackers to execute arbitrary code by tricking users into opening spec...

May 27, 2022
CVE-2022-1735 7.8

CVE-2022-1735 is a classic buffer overflow vulnerability in Vim text editor versions prior to 8.2.4969. Attackers can exploit this by tricking users i...

May 17, 2022
CVE-2022-1733 7.8

CVE-2022-1733 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2.4968. Attackers can exploit this by tricking user...

May 17, 2022
CVE-2022-1629 7.8

CVE-2022-1629 is a buffer over-read vulnerability in Vim's find_next_quote function that could allow attackers to crash the application, modify memory...

May 10, 2022
CVE-2022-1619 7.8

CVE-2022-1619 is a heap-based buffer overflow vulnerability in Vim's command-line editing function that could allow attackers to crash the application...

May 8, 2022
CVE-2022-1616 7.8

CVE-2022-1616 is a use-after-free vulnerability in Vim's append_command function that allows attackers to crash the application, bypass memory protect...

May 7, 2022
CVE-2022-1381 7.8

CVE-2022-1381 is a heap buffer overflow vulnerability in Vim's skip_range function that allows attackers to crash the application, bypass memory prote...

Apr 18, 2022
CVE-2022-1154 7.8

CVE-2022-1154 is a use-after-free vulnerability in Vim's utf_ptr2char function that could allow an attacker to execute arbitrary code or cause a denia...

Mar 30, 2022
CVE-2022-0943 7.8

CVE-2022-0943 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2.4563. Attackers can exploit this by tricking user...

Mar 14, 2022
CVE-2022-0729 8.8

CVE-2022-0729 is a use-after-free vulnerability in Vim's memory handling that allows an attacker to execute arbitrary code by tricking a user into ope...

Feb 23, 2022
CVE-2022-0685 7.8

CVE-2022-0685 is a memory corruption vulnerability in Vim text editor caused by an out-of-range pointer offset. Attackers can exploit this by tricking...

Feb 20, 2022
CVE-2022-0629 7.8

CVE-2022-0629 is a stack-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code...

Feb 17, 2022
CVE-2022-0443 7.8

CVE-2022-0443 is a use-after-free vulnerability in Vim text editor versions prior to 8.2. This memory corruption flaw could allow attackers to execute...

Feb 2, 2022
CVE-2022-0417 7.8

CVE-2022-0417 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Feb 1, 2022

Why Monitor Vim Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 64+ known vulnerabilities affecting Vim products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Vim packages in under 60 seconds. No agents required - completely agentless scanning that works across Vim deployments.

Free vulnerability database: Access detailed information about every Vim CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Vim CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Vim CVEs Free