No. The iCalendar import, RSS feed portlet, collective.icalendar, and RestrictedPython issues have CVE identifiers. The TALES injection issue and the excessive title, description, or filename length issue are listed as having CVEs requested.
The denial-of-service issue caused by excessive title, description, or filename length has fixes in both plone.app.dexterity and plone.app.contenttypes.
Yes. A denial-of-service vulnerability is reported in collective.icalendar, and a sandbox escape is reported in RestrictedPython. These are separate from the issues reported in plone.app.portlets, plone.app.event, plone.app.dexterity, and plone.app.contenttypes.
The TALES injection remote code execution issue is rated 9.9 critical. The iCalendar import and RSS feed portlet denial-of-service issues are each rated 9.1 critical.