<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:37:51.746735+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14527</id>
    <title>bdu:2026-14527</title>
    <updated>2026-10-04T07:37:51.950948+00:00</updated>
    <content>bdu:2026-14527</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43961</id>
    <title>BELL-CVE-2026-43961</title>
    <updated>2026-10-04T07:37:51.950988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: vim, Alpaquita:25: vim, Alpaquita:stream: vim</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43961"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373389</id>
    <title>EUVD-2026-373389</title>
    <updated>2026-10-04T07:37:51.951019+00:00</updated>
    <content>EUVD-2026-373389</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373389"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43961</id>
    <title>fkie_cve-2026-43961</title>
    <updated>2026-10-04T07:37:51.951032+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43961"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2553</id>
    <title>OESA-2026-2553 — vim security update</title>
    <updated>2026-10-04T07:37:51.951059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: vim</p>
<p>Vim is an advanced text editor that seeks to provide the power of the de-facto Unix editor &amp;amp;apos;Vi&amp;amp;apos;, with a more complete feature set. Vim is a highly configurable text editor built to enable efficient text editing. It is an improved version of the vi editor distributed with most UNIX systems.

Security Fix(es):</p>
<p>A vulnerability has been found in vim up to 9.2.479 (Word Processing Software) and classified as critical. The CWE definition for the vulnerability is CWE-94. The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. As an impact it is known to affect confidentiality, integrity, and availability. Upgrading to version 9.2.480 eliminates this vulnerability.(CVE-2026-43961)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2553"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11114-1</id>
    <title>openSUSE-SU-2026:11114-1 — gvim-9.2.0530-1.1 on GA media</title>
    <updated>2026-10-04T07:37:51.951088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gvim-9.2.0530-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11114-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:57614</id>
    <title>RHSA-2026:57614 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-04T07:37:51.951109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vim: arbitrary command execution via modeline sandbox bypass vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass vim: Vim: Arbitrary code execution via command injection in NetBeans interface vim: Command injection allows arbitrary code execution via malicious tag files vim: Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution vim: Vim: Arbitrary command execution via :find command-line completion vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service vim: command injection when decompressing .tgz archives vim: Vim: Arbitrary Code Execution via crafted directory names vim: Vim: Arbitrary code execution via crafted step-definition patterns vim: Vim: Arbitrary code execution via Python omni-completion vim: Vim: Denial of Service via out-of-bounds write in terminal handling vim: Vim: Arbitrary code execution through Python omni-completion. vim: Vim: Denial of service via crafted undo file vim: Vim: Arbitrary code execution via crafted zip archive entry names vim: Vim: Out-of-bounds Read with Text Properties vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:57614"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21833-1</id>
    <title>SUSE-SU-2026:21833-1 — Security update for vim</title>
    <updated>2026-10-04T07:37:51.951148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for vim</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21833-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43961</id>
    <title>UBUNTU-CVE-2026-43961</title>
    <updated>2026-10-04T07:37:51.951165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: vim, Ubuntu:Pro:16.04:LTS: vim, Ubuntu:Pro:18.04:LTS: vim, Ubuntu:Pro:20.04:LTS: vim, Ubuntu:22.04:LTS: vim, Ubuntu:24.04:LTS: vim, Ubuntu:25.10: vim, Ubuntu:26.04:LTS: vim</p>
<p>A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43961"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1548</id>
    <title>WID-SEC-W-2026-1548 — vim: Mehrere Schwachstellen ermöglichen Codeausführung</title>
    <updated>2026-10-04T07:37:51.951322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vim ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1548"/>
  </entry>
</feed>
