CVEs affecting projects tracked on Release Alert, from NVD & OSV.
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware