EEYE, a security firm, has a list of problems it's discovered with software.
Some are severe.
Not only has the page got the number of days overdue since the vulnerabilities were first discovered, the same page,
on the Research link, has a useful set of tools.