SecAlerts
A

Actual

Security Risk Profile

39
/100
low

Security Risk Score

Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 21, 2024 to present

6
Total CVEs
3
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
39/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
2
High
1
Medium
3
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
Path Traversal
2
2
Infoleak
1
3
Command Injection
1

Most Affected Products

1. npm/@actual-app/sync-server2
2. ActualBudget Actual Node.js2
3. Actual Actual Sync Server1
4. Actual actual-server1
5. Actual Actual Budget sync-server1

Recent Vulnerabilities

See more →

Monitor Actual in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Actual Security Vulnerabilities & Risk Score | 6 CVEs | SecAlerts - SecAlerts