CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.