Look up known vulnerabilities affecting an open-source dependency — npm, PyPI, Go, Maven, NuGet, crates.io, RubyGems and more — with the exact affected version ranges, from the OSV.dev / GitHub Security Advisory (GHSA) database, cross-referenced to CVE.