CVEs affecting projects tracked on Release Alert, from NVD & OSV.
corenlp is vulnerable to Improper Restriction of XML External Entity Reference