CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Joplin before 2.0.9 allows XSS via button and form in the note body.