<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Ionic Framework (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ionic.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ionic-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Ionic Framework (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-62627 – An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62627</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62627</strong></p>
  <p>An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62624 – A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62624</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62624</strong></p>
  <p>A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62623 – A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62623</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62623</strong></p>
  <p>A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39502 – In the Linux kernel, the following vulnerability has been resolved:

ionic: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39502</guid>
    <pubDate>Fri, 12 Jul 2024 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39502</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: fix use after netif_napi_del()  When queues are started, netif_napi_add() and napi_enable() are called. If there are 4 queues and only 3 queues are used for the current configuration, only 3 queues' napi should be registered and enabled. The ionic_qcq_enable() checks whether the .poll pointer is not NULL for enabling only…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16202 – Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16202</guid>
    <pubDate>Wed, 09 Jan 2019 23:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16202</strong></p>
  <p>Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1000123 – Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca01...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000123</guid>
    <pubDate>Tue, 13 Mar 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1000123</strong></p>
  <p>Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other sensitive data leakage. This attack appear to be exploitable via Attacker must have access to victim's iOS logs. This vulnerability appears to have been fixed i…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000123">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
