CVE Tracker
13 recordsEvery published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | EPSS | KEV sources | Patch window | Vendor / product | Summary | Published |
|---|
| CVE-2026-47162 | 8.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 86d ago |
| CVE-2026-51400 | 8.4 | — | — | — | vim / vim | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfil | 32d ago |
| CVE-2026-52859 | 8.2 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 86d ago |
| CVE-2026-59858 | 7.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 58d ago |
| CVE-2026-59856 | 7.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 58d ago |
| CVE-2026-57456 | 7.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 72d ago |
| CVE-2026-57455 | 7.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 72d ago |
| CVE-2026-55895 | 7.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 72d ago |
| CVE-2026-55693 | 7.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 72d ago |
| CVE-2026-52860 | 7.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 86d ago |
| CVE-2026-52858 | 7.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 86d ago |
| CVE-2026-51401 | 7.7 | — | — | — | vim / vim | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfil | 32d ago |
| CVE-2026-32249 | 5.3 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 177d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE); CISA KEV, ENISA EUVD, CIRCL and VulnCheck (exploitation status, four independent catalogues); FIRST EPSS (exploitation probability). Patch window is the gap between CVE publication and the earliest KEV listing, so a negative value means a catalogue called it exploited before it was disclosed. Data refreshes every five hours.