KNIME AG maintains a focused analytics and data-science platform portfolio centered on its KNIME Analytics Platform, KNIME Server, and KNIME Business Hub, which serve as integration and orchestration points for data workflows and business intelligence. The vendor's vulnerabilities recur through web-facing input-handling and resource-control weakness classes—including path traversal, cross-site scripting, code injection, and resource exhaustion—characteristic of platforms that parse user-supplied configurations and execute dynamic workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by KNIME AG over time
Of all the CVEs published by KNIME AG as a CNA, 92.3% affect products that KNIME AG develops as a vendor.
Of all the CVEs published that affect products developed by KNIME AG, 70.6% are self-published by KNIME AG as a CNA.
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2402HIGH A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in posse | Mar 31, 2025 | 8.6 | 26 | NO | NO |
CVE-2025-2787HIGH KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete t | Mar 26, 2025 | 8.8 | 26 | NO | NO |
CVE-2022-44748HIGH A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritten on the server's file system. | Nov 24, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-44749HIGH A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files being overwritten on the user's | Nov 24, 2022 | 7.0 | 24 | NO | NO |
CVE-2022-31500HIGH In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions. | Jun 2, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-44725HIGH KNIME Server before 4.13.4 allows directory traversal in a request for a client profile. | Dec 8, 2021 | 7.5 | 24 | NO | NO |
CVE-2025-11240HIGH An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub insta | Oct 2, 2025 | 7.2 | 23 | NO | NO |
CVE-2025-3019HIGH KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java | Mar 31, 2025 | 7.2 | 21 | NO | NO |
CVE-2021-44726MEDIUM KNIME Server before 4.13.4 allows XSS via the old WebPortal login page. | Dec 8, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-45097MEDIUM KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allow | Dec 16, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by KNIME AG.
Media articles that mention a CVE ID that affects a product developed by KNIME AG — matched by CVE ID, not by vendor name.