CVEs affecting projects tracked on Release Alert, from NVD & OSV.
OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.