Products: 1
Vulnerabilities: 12
Known Exploited: 0
0
Critical Level Threats
4
High Level Threats
4
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-49229
Actual: Disabled OpenID users keep access through existing session tokens
Last Modified: Jul 09, 2026
Published: Jul 07, 2026
CVE-2026-50179
Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
Last Modified: Jul 09, 2026
Published: Jul 07, 2026
CVE-2026-46700
Actual: Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
Last Modified: Jul 08, 2026
Published: Jul 07, 2026
CVE-2026-46672
Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper
Last Modified: Jul 08, 2026
Published: Jul 07, 2026
CVE-2026-50007
Actual: Shared users can perform owner-only file management actions
Last Modified: Jul 07, 2026
Published: Jul 07, 2026
Items Per Page
