CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.