Known Vulnerabilities for E-Bridge by Weaver
Listed below are 10 of the newest known vulnerabilities associated with "E-Bridge" by "Weaver".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-102878 json | mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to b... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-100868 json | Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-100722 json | vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, ... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-100664 json | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseu... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-100585 json | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code p... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-98026 json | In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: properly convert mglist to rcu Sash... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-97615 json | In the Linux kernel, the following vulnerability has been resolved: net: bridge: use option bits for CFM/MRP frame handlers ... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-97436 json | In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: rework FDB management on the bridge leave ... | Not Provided | 2026-09-24 | 2026-09-25 |
| CVE-2026-93606 json | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93603 json | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib... | Not Provided | 2026-09-18 | 2026-09-22 |