CVEs affecting projects tracked on Release Alert, from NVD & OSV.
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.