CVEs affecting projects tracked on Release Alert, from NVD & OSV.
JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java.