CVEs affecting projects tracked on Release Alert, from NVD & OSV.
verdaccio before 3.12.0 allows XSS.