CVEs affecting projects tracked on Release Alert, from NVD & OSV.
NPM package next-npm-version1.0.1 is vulnerable to Command injection.