CVEs affecting projects tracked on Release Alert, from NVD & OSV.
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.