CVEs affecting projects tracked on Release Alert, from NVD & OSV.
parse-server before 3.4.1 allows DoS after any POST to a volatile class.