CVEs affecting projects tracked on Release Alert, from NVD & OSV.
givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.