bin/mk-notes: correct the anchor links to the CVE descriptions