CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Rejected reason: User data field is not attacker controlled