Skip to main content

Vendor/product archive

neovim / neovim CVEs

Beta · best-effort

6 CVEs tagged to neovim / neovim0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-45130

Published May 8, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (…

CVSS 6.6 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-25749

Published Feb 6, 2026

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'hel…

CVSS 6.6 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2019-12735

Published Jun 5, 2019

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execut…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1