Maven package intelligence

org.primefaces:primefaces Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.primefaces:primefaces, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting org.primefaces:primefaces
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.primefaces:primefaces KEVs with sensor-observed exploitation activity

Review org.primefaces:primefaces exploitation against the versions you run

All one exploited org.primefaces:primefaces vulnerability tracked here is also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.primefaces:primefaces vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2017-1000486

Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

In CISA 10 Jan 2022

Recurring weakness patterns

Inadequate Encryption Strength account for mapped occurrences across this org.primefaces:primefaces KEV portfolio.

Browse all KEVs →