CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Open-AudIT 3.3.0 allows an XSS attack after login.