CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Flawfinder output manipulation via untrusted filenames and source text