Knime
17 known vulnerabilities
Top Products
A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other
An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker
Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'
KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a m
A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones lis
KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects
A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It a
An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When
Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME Business Hub before 1.4.0 has left users vulne
The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above c
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arb
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's passwo
KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (
KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.
Frequently Asked Questions
How many CVEs affect Knime?
Knime has 17 CVE records in our database, including 0 critical and 8 high severity vulnerabilities.
What are the most severe Knime vulnerabilities?
Knime has 0 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Knime vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Knime products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Knime Vulnerabilities
CyberStrike scans your infrastructure for Knime vulnerabilities and provides real-time remediation guidance.
Get Started