CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Dependency-Track before 3.5.1 allows XSS.