Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Knime

17 known vulnerabilities

8
HIGH
8
MEDIUM
1
LOW

Top Products

business hub 9 knime analytics platform 4 knime server 4
17 CVEs
4.3
CVE-2025-14262

A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other

7.2
CVE-2025-11240

An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker

4.3
CVE-2025-11239

Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'

7.2
CVE-2025-3019

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a m

8.6
CVE-2025-2402

A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones lis

8.8
CVE-2025-2787

KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects

6.5
CVE-2024-6598

A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It a

6.1
CVE-2023-5562

An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When

4.3
CVE-2023-3140

Missing HTTP headers (X-Frame-Options, Content-Security-Policy) in KNIME Business Hub before 1.4.0 has left users vulne

5.3
CVE-2023-2541

The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about

5.5
CVE-2022-44749

A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above c

7.1
CVE-2022-44748

A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arb

7.8
CVE-2022-31500

In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.

2.9
CVE-2021-45097

KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's passwo

4.7
CVE-2021-45096

KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (

8.8
CVE-2021-44726

KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.

7.5
CVE-2021-44725

KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.

Frequently Asked Questions

How many CVEs affect Knime?

Knime has 17 CVE records in our database, including 0 critical and 8 high severity vulnerabilities.

What are the most severe Knime vulnerabilities?

Knime has 0 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Knime vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Knime products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Knime Vulnerabilities

CyberStrike scans your infrastructure for Knime vulnerabilities and provides real-time remediation guidance.

Get Started