CVEs affecting projects tracked on Release Alert, from NVD & OSV.
The Chartkick gem through 3.1.0 for Ruby allows XSS.