<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:40:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14501</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14501</link>
      <description>bdu:2026-14501</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14501</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-57453</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-57453</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: vim, Alpaquita:25: vim, Alpaquita:stream: vim&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: vim, Alpaquita:25: vim, Alpaquita:stream: vim&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-57453</guid>
    </item>
    <item>
      <title>EUVD-2026-330657</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330657</link>
      <description>EUVD-2026-330657</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330657</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57453</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57453</link>
      <description>&lt;p&gt;Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57453</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-57453 — Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-57453</link>
      <description>msrc_CVE-2026-57453</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-57453</guid>
    </item>
    <item>
      <title>RHSA-2026:57614 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:57614</link>
      <description>&lt;p&gt;vim: arbitrary command execution via modeline sandbox bypass vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass vim: Vim: Arbitrary code execution via command injection in NetBeans interface vim: Command injection allows arbitrary code execution via malicious tag files vim: Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution vim: Vim: Arbitrary command execution via :find command-line completion vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service vim: command injection when decompressing .tgz archives vim: Vim: Arbitrary Code Execution via crafted directory names vim: Vim: Arbitrary code execution via crafted step-definition patterns vim: Vim: Arbitrary code execution via Python omni-completion vim: Vim: Denial of Service via out-of-bounds write in terminal handling vim: Vim: Arbitrary code execution through Python omni-completion. vim: Vim: Denial of service via crafted undo file vim: Vim: Arbitrary code execution via crafted zip archive entry names vim: Vim: Out-of-bounds Read with Text Properties vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vim: arbitrary command execution via modeline sandbox bypass vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass vim: Vim: Arbitrary code execution via command injection in NetBeans interface vim: Command injection allows arbitrary code execution via malicious tag files vim: Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution vim: Vim: Arbitrary command execution via :find command-line completion vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service vim: command injection when decompressing .tgz archives vim: Vim: Arbitrary Code Execution via crafted directory names vim: Vim: Arbitrary code execution via crafted step-definition patterns vim: Vim: Arbitrary code execution via Python omni-completion vim: Vim: Denial of Service via out-of-bounds write in terminal handling vim: Vim: Arbitrary code execution through Python omni-completion. vim: Vim: Denial of service via crafted undo file vim: Vim: Arbitrary code execution via crafted zip archive entry names vim: Vim: Out-of-bounds Read with Text Properties vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:57614</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-57453</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-57453</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: vim&lt;/p&gt;
&lt;p&gt;Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: vim&lt;/p&gt;
&lt;p&gt;Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command by inserting archive entry names that are quoted only for the shell, not for PowerShell. A crafted entry name can break out of the intended string context and cause PowerShell to execute arbitrary commands with the privileges of the user running Vim, triggered by opening, viewing or extracting the archive. This vulnerability is fixed in 9.2.0678.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-57453</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2026 — vim: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2026</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vim ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vim ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2026</guid>
    </item>
  </channel>
</rss>
