Neovim
Security Risk Profile
43
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 7 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 5, 2019 to present
7
Total CVEs
2
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
43/100
medium
Severity Distribution
Critical
0High
2Medium
4Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
4
2
Command Injection
1
3
Integer Overflow
1
4
Use After Free
1
5
OS Command Injection
1
Most Affected Products
1. vim Vim9
2. Neovim Neovim7
3. debian/vim5
4. Debian Debian Linux3
5. NetApp Bootstrap Os2
Recent Vulnerabilities
See more →CVE-2026-11487
CVSS 1.9low
Neovim View Branch secure.lua M.read command injection
6/8/2026🔧 No Patch
CVE-2026-45130
CVSS 6.6medium
Vim: Heap Buffer Overflow in spell file loading
5/8/2026
CVE-2026-25749
CVSS 6.6EPSS 0%medium
Heap Overflow in Vim
2/6/2026🔧 No Patch
CVE-2025-22134
CVSS 5.5EPSS 0%medium
heap-buffer-overflow with visual mode in Vim < 9.1.1003
1/13/2025
CVE-2024-43374
CVSS 4.7medium
Vim heap-use-after-free in src/arglist.c:207
8/15/2024
CVE-2021-4019
CVSS 7.8high
Heap-based Buffer Overflow in vim/vim
12/1/2021
CVE-2019-12735
CVSS 8.6high
6/5/2019
Monitor Neovim in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.