CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.