CVEs affecting projects tracked on Release Alert, from NVD & OSV.
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.