CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Misskey before 10.102.4 allows hijacking a user's token.