Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

KNIME AG

First CVE: Dec 8, 2021Active for: 5 yearsTotal CVEs: 17
27.8
VTI Score
Low

KNIME AG maintains a focused analytics and data-science platform portfolio centered on its KNIME Analytics Platform, KNIME Server, and KNIME Business Hub, which serve as integration and orchestration points for data workflows and business intelligence. The vendor's vulnerabilities recur through web-facing input-handling and resource-control weakness classes—including path traversal, cross-site scripting, code injection, and resource exhaustion—characteristic of platforms that parse user-supplied configurations and execute dynamic workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by KNIME AG over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 8, 2021
4 years ago
Most Recent CVE
Dec 8, 2025
228 days ago

Self-Reporting Analysis

Of all the CVEs published by KNIME AG as a CNA, 92.3% affect products that KNIME AG develops as a vendor.

92.3%
Self-reported: 12 (92.3%)
Third-party: 1 (7.7%)

Of all the CVEs published that affect products developed by KNIME AG, 70.6% are self-published by KNIME AG as a CNA.

70.6%
29.4%
Self-published: 12 (70.6%)
Other CNAs: 5 (29.4%)

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-2402HIGH
A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in posse
Mar 31, 20258.626NONO
CVE-2025-2787HIGH
KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete t
Mar 26, 20258.826NONO
CVE-2022-44748HIGH
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritten on the server's file system.
Nov 24, 20227.525NONO
CVE-2022-44749HIGH
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files being overwritten on the user's
Nov 24, 20227.024NONO
CVE-2022-31500HIGH
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
Jun 2, 20227.824NONO
CVE-2021-44725HIGH
KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.
Dec 8, 20217.524NONO
CVE-2025-11240HIGH
An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub insta
Oct 2, 20257.223NONO
CVE-2025-3019HIGH
KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java
Mar 31, 20257.221NONO
CVE-2021-44726MEDIUM
KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
Dec 8, 20216.121NONO
CVE-2021-45097MEDIUM
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allow
Dec 16, 20215.520NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
53%
47%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (17.6%)
Network14 (82.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High2 (11.8%)
Unknown0 (0.0%)
User Interaction
None12 (70.6%)
Unknown0 (0.0%)
Required5 (29.4%)
Privileges Required
Low7 (41.2%)
High0 (0.0%)
None10 (58.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by KNIME AG.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by KNIME AG — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For KNIME AG's Products

View all 2 CNAs →

Top CWEs