KNIME AG
First CVE: Nov 24, 2022Active for: 4 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
2.6
Avg CVEs / Year
More Avg CVEs / Year than 18% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 20% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by KNIME AG as a CNA, 92.3% affect products that KNIME AG develops as a vendor.
92.3%
Self-reported: 12Third-party: 1
Of all the CVEs published that affect products developed by KNIME AG, 70.6% are self-published by KNIME AG as a CNA.
70.6%
29.4%
Self-published: 12Published by other CNAs: 5
Trends Over Time
The number and severity of CVEs published by KNIME AG over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2022
3 years ago
Most Recent CVE
Mar 24, 2026
122 days ago
Top CVEs
All CVEs published by KNIME AG as a CNA, regardless of affected vendor or product.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2402HIGH A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in posse | Mar 31, 2025 | 8.6 | 26 | NO | NO |
CVE-2025-2787HIGH KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete t | Mar 26, 2025 | 8.8 | 26 | NO | NO |
CVE-2022-44748HIGH A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritten on the server's file system. | Nov 24, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-44749HIGH A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files being overwritten on the user's | Nov 24, 2022 | 7.0 | 24 | NO | NO |
CVE-2025-11240HIGH An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub insta | Oct 2, 2025 | 7.2 | 23 | NO | NO |
CVE-2025-3019HIGH KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java | Mar 31, 2025 | 7.2 | 21 | NO | NO |
CVE-2026-4649MEDIUM Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026 | Mar 24, 2026 | 5.3 | 20 | NO | NO |
CVE-2023-5562MEDIUM An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When KNIME Analytics Platform is used as an executor for either K | Oct 12, 2023 | 6.1 | 19 | NO | NO |
CVE-2025-11239MEDIUM Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user's team. Starting with KNIME Business Hub 1.16.0 only metadat | Oct 2, 2025 | 4.3 | 18 | NO | NO |
CVE-2024-6598MEDIUM A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It allows an authenticated attacker with job execution privilege | Jul 9, 2024 | 6.5 | 18 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA13 CVEs
54%
46%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None10 (76.9%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low6 (46.2%)
High0 (0.0%)
None7 (53.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by KNIME AG as a CNA.
Media Mentions
Media articles that mention a CVE ID published by KNIME AG as a CNA — matched by CVE ID, not by organization name.