
actual-app @actual-app/sync-server Vulnerabilities
CVE security advisories and vulnerability history for @actual-app/sync-server by actual-app.
Last updated

CVE security advisories and vulnerability history for @actual-app/sync-server by actual-app.
Last updated
actual-app @actual-app/sync-server has 6 published CVE records since 2026, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 6 have a known public exploit. The average CVSS base score across scored CVEs is 6.7.
This page aggregates every publicly disclosed vulnerability (CVE) affecting actual-app @actual-app/sync-server, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
How the CVSS severity of actual-app @actual-app/sync-server's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of actual-app @actual-app/sync-server's CVEs are currently listed in CISA's KEV catalog.
Public exploits
6
6 of actual-app @actual-app/sync-server's CVEs have a known public exploit available.
Browse every actual-app @actual-app/sync-server version named in a CVE, then pick one to see only the CVEs that affect it.
6 CVEs
The CWE weakness categories most often found in actual-app @actual-app/sync-server CVEs. Follow any weakness for its full explanation.
Browse vulnerabilities for other products by actual-app.
Common questions about actual-app @actual-app/sync-server vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new actual-app @actual-app/sync-server vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.