CVEs affecting projects tracked on Release Alert, from NVD & OSV.
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI.