16 CVEs affecting Nearform products, 0 known to be exploited (CISA KEV), with EPSS scores. Most affected: Fast-Jwt, Get-Jwks, Urql.