CVEs affecting projects tracked on Release Alert, from NVD & OSV.
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.