CVEs affecting projects tracked on Release Alert, from NVD & OSV.
In Jellyfin before 10.8, stored XSS allows theft of an admin access token.