CVEs affecting projects tracked on Release Alert, from NVD & OSV.
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.