CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Joplin before 2.11.5 allows XSS via a USE element in an SVG document.