Known vulnerabilities in vim (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:vim_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 42
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting vim (Red Hat package) vim (Red Hat package) is affected by 42 known vulnerabilities: 27 high, 5 medium, 10 low Critical High Medium Low

Vulnerabilities (42)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU135702 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-59856
CWE-94 High
No
No
8.2.2637-26.el9_8.13 29.06.2026 SB2026062909
SB20260715103
SB2026072430
and 4 more
#VU135701 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-59858
CWE-94 Medium
No
No
8.0.1763-31.el8_10, 8.2.2637-26.el9_8.13 29.06.2026 SB2026062908
SB20260715103
SB2026072526
and 5 more
#VU134978 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-57456
CWE-94 High
No
No
8.0.1763-31.el8_10, 8.2.2637-26.el9_8.13 22.06.2026 SB2026062216
SB2026070315
SB2026071933
and 3 more
#VU134977 - Out-of-bounds write
CVE-2026-57455
CWE-787 Low
No
No
8.0.1763-31.el8_10, 8.2.2637-26.el9_8.13 22.06.2026 SB2026062215
SB2026070315
SB2026071933
and 3 more
#VU134580 - Out-of-bounds write
CVE-2026-55693
CWE-787 Medium
No
No
8.0.1763-31.el8_10, 8.2.2637-26.el9_8.13 16.06.2026 SB2026061605
SB2026070315
SB2026070617
and 6 more
#VU131544 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-46483
CWE-78 Low
No
No
8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3 15.05.2026 SB2026051517
SB2026052130
SB2026052523
and 20 more
#VU126870 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-41411
CWE-78 Medium
No
No
8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.0.1763-24.el8_10, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 8.2.2637-26.el9_8.6, 9.1.083-9.el10_2.4 22.04.2026 SB20260422223
SB2026050840
SB20260509158
and 16 more
#VU125037 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-34982
CWE-78 High
No
No
8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 8.2.2637-23.el9_7.3, 9.1.083-6.el10_1.4 07.04.2026 SB2026040792
SB2026041439
SB20260417153
and 13 more
#VU125036 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-35177
CWE-22 Medium
No
No
8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 9.1.083-9.el10_2.3 07.04.2026 SB2026040793
SB2026042846
SB2026050311
and 10 more
#VU124153 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-33412
CWE-78 Medium
No
No
7.4.629-5.el6_10.3, 7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10.1, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.2, 9.1.083-5.el10_0.2, 9.1.083-6.el10_1.3 20.03.2026 SB2026032022
SB20260325108
SB20260325109
and 23 more
#VU123427 - Heap-based Buffer Overflow
CVE-2026-28421
CWE-122 High
No
No
7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10.1, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.2, 9.1.083-5.el10_0.2, 9.1.083-6.el10_1.3 03.03.2026 SB2026030329
SB2026030546
SB2026030620
and 25 more
#VU123423 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-28417
CWE-78 High
No
No
7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10.1, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.2, 9.1.083-5.el10_0.2, 9.1.083-6.el10_1.3 03.03.2026 SB2026030317
SB2026030620
SB2026030621
and 28 more
#VU122421 - Heap-based Buffer Overflow
CVE-2026-25749
CWE-122 High
No
No
7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.1, 9.1.083-5.el10_0.2 05.02.2026 SB2026020601
SB2026021309
SB2026021310
and 19 more
#VU112980 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-53905
CWE-22 High
No
No
8.0.1763-21.el8_10, 8.2.2637-20.el9_4.1, 8.2.2637-22.el9_6.1, 9.1.083-5.el10_0.1 16.07.2025 SB2025071691
SB2025071770
SB2025071771
and 23 more
#VU112979 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-53906
CWE-22 High
No
No
8.0.1763-21.el8_10, 8.2.2637-20.el9_4.1, 8.2.2637-22.el9_6.1, 9.1.083-5.el10_0.1 16.07.2025 SB2025071690
SB2025071770
SB2025071771
and 29 more
#VU71559 - NULL Pointer Dereference
CVE-2022-47024
CWE-476 Low
No
No
8.2.2637-20.el9_1 26.01.2023 SB2023012623
SB2023013121
SB2023022848
and 16 more
#VU64508 - Out-of-bounds read
CVE-2022-1927
CWE-125 Low
No
No
8.0.1763-19.el8_6.4, 8.2.2637-16.el9_0.3 20.06.2022 SB2022062022
SB2022080332
SB2022080610
and 49 more
#VU64506 - Out-of-bounds write
CVE-2022-1897
CWE-787 Low
No
No
8.0.1763-19.el8_6.4, 8.2.2637-16.el9_0.3 20.06.2022 SB2022062022
SB2022070807
SB2022080332
and 48 more
#VU63487 - Out-of-bounds write
CVE-2022-1785
CWE-787 High
No
No
8.0.1763-19.el8_6.4, 8.2.2637-16.el9_0.3 20.05.2022 SB2022052017
SB2022062022
SB2022063027
and 47 more
#VU63060 - Heap-based Buffer Overflow
CVE-2021-3903
CWE-122 High
No
No
8.2.2637-21.el9 11.05.2022 SB2022051173
SB2021111514
SB2022062022
and 39 more


Showing elements 1 - 20 out of 42