KNIME AG

First CVE: Nov 24, 2022Active for: 4 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
2.6
Avg CVEs / Year
More Avg CVEs / Year than 18% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 20% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by KNIME AG as a CNA, 92.3% affect products that KNIME AG develops as a vendor.

92.3%
Self-reported: 12Third-party: 1

Of all the CVEs published that affect products developed by KNIME AG, 70.6% are self-published by KNIME AG as a CNA.

70.6%
29.4%
Self-published: 12Published by other CNAs: 5

Trends Over Time

The number and severity of CVEs published by KNIME AG over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2022
3 years ago
Most Recent CVE
Mar 24, 2026
122 days ago

Top CVEs

All CVEs published by KNIME AG as a CNA, regardless of affected vendor or product.

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in posse
Mar 31, 20258.626NONO
KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete t
Mar 26, 20258.826NONO
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritten on the server's file system.
Nov 24, 20227.525NONO
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files being overwritten on the user's
Nov 24, 20227.024NONO
An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub insta
Oct 2, 20257.223NONO
KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java
Mar 31, 20257.221NONO
Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026
Mar 24, 20265.320NONO
An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When KNIME Analytics Platform is used as an executor for either K
Oct 12, 20236.119NONO
Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user's team. Starting with KNIME Business Hub 1.16.0 only metadat
Oct 2, 20254.318NONO
A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It allows an authenticated attacker with job execution privilege
Jul 9, 20246.518NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA13 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None10 (76.9%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low6 (46.2%)
High0 (0.0%)
None7 (53.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by KNIME AG as a CNA.

Media Mentions

Media articles that mention a CVE ID published by KNIME AG as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs