CVEs affecting projects tracked on Release Alert, from NVD & OSV.
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.