4 CVEs affecting Supabase products, 0 known to be exploited (CISA KEV), with EPSS scores. Most affected: Auth, Auth-Js, Postgres, Realtime.