<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:40:40.648638+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14501</id>
    <title>bdu:2026-14501</title>
    <updated>2026-10-04T15:40:40.657717+00:00</updated>
    <content>bdu:2026-14501</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14501"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-57453</id>
    <title>BELL-CVE-2026-57453</title>
    <updated>2026-10-04T15:40:40.657755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: vim, Alpaquita:25: vim, Alpaquita:stream: vim</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-57453"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330657</id>
    <title>EUVD-2026-330657</title>
    <updated>2026-10-04T15:40:40.657786+00:00</updated>
    <content>EUVD-2026-330657</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330657"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57453</id>
    <title>fkie_cve-2026-57453</title>
    <updated>2026-10-04T15:40:40.657799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57453"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-57453</id>
    <title>msrc_CVE-2026-57453 — Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction</title>
    <updated>2026-10-04T15:40:40.657825+00:00</updated>
    <content>msrc_CVE-2026-57453</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-57453"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:57614</id>
    <title>RHSA-2026:57614 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-04T15:40:40.657843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vim: arbitrary command execution via modeline sandbox bypass vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass vim: Vim: Arbitrary code execution via command injection in NetBeans interface vim: Command injection allows arbitrary code execution via malicious tag files vim: Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution vim: Vim: Arbitrary command execution via :find command-line completion vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service vim: command injection when decompressing .tgz archives vim: Vim: Arbitrary Code Execution via crafted directory names vim: Vim: Arbitrary code execution via crafted step-definition patterns vim: Vim: Arbitrary code execution via Python omni-completion vim: Vim: Denial of Service via out-of-bounds write in terminal handling vim: Vim: Arbitrary code execution through Python omni-completion. vim: Vim: Denial of service via crafted undo file vim: Vim: Arbitrary code execution via crafted zip archive entry names vim: Vim: Out-of-bounds Read with Text Properties vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:57614"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-57453</id>
    <title>UBUNTU-CVE-2026-57453</title>
    <updated>2026-10-04T15:40:40.657886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:26.04:LTS: vim</p>
<p>Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-57453"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2026</id>
    <title>WID-SEC-W-2026-2026 — vim: Mehrere Schwachstellen</title>
    <updated>2026-10-04T15:40:40.657936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vim ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2026"/>
  </entry>
</feed>
