CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.