CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.