CVEs affecting projects tracked on Release Alert, from NVD & OSV.
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.