I’d assume a number of these would be due to the good old “docker punching a hole through UFW”, which still hasn’t been fixed.
(luckily, all just pet projects with no sensitive stuff - still…)
For more on Docker's built-in chains, see: https://docs.docker.com/network/iptables/#add-iptables-polic...
Most programs still bind to 0.0.0.0 and that's not a problem if your firewall works the way you expect it to. Docker's firewall rules overriding UFW's firewall rules without notice is unexpected for many people.
I know I fell for this one years ago when I first messed around with Docker, luckily I wasn't running anything important.