CVEs affecting projects tracked on Release Alert, from NVD & OSV.
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.