CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.