CVEs affecting projects tracked on Release Alert, from NVD & OSV.
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.