CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.