Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-11240 An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legi… Business Hub 1.16.0+ Fix from $1,9502025-10-02 HIGH 7.2 CVE-2025-3019 KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a mali… Business Hub 1.12.4 / 1.13.3+ Fix from $1,9502025-03-31 HIGH 8.6 CVE-2025-2402 A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthent… Business Hub 1.10.3 / 1.11.3+ Fix from $1,9502025-03-31 HIGH 8.8 CVE-2025-2787 KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component.… Business Hub 1.10.4 / 1.11.4+ Fix from $1,9502025-03-26 MEDIUM 6.5 CVE-2024-6598 A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It allows an authenticated attack… Business Hub 1.10.2+ Fix from $1,6002024-07-09 MEDIUM 6.1 CVE-2023-5562 An unsafe default configuration in KNIME Analytics Platform before 5.2.0 allows for a cross-site scripting attack. When KNIME Analytics Platform is u… Knime Analytics Platform 5.2.0+ Fix from $1,6002023-10-12 MEDIUM 5.3 CVE-2023-2541 The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about the application such as versi… Business Hub 1.4.0+ Fix from $1,6002023-06-07 HIGH 7.0 CVE-2022-44749 A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files … Knime Analytics Platform 4.6.4+ Fix from $1,9502022-11-24 HIGH 7.5 CVE-2022-44748 A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritte… Knime Server 4.13.6 / 4.14.3+ Fix from $1,9502022-11-24 HIGH 7.8 CVE-2022-31500 In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions. Knime Analytics Platform 4.6.0+ Fix from $1,9502022-06-02 MEDIUM 5.5 CVE-2021-45097 KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropri… Knime Server 4.13.4+ Fix from $1,6002021-12-16 HIGH 7.5 CVE-2021-44725 KNIME Server before 4.13.4 allows directory traversal in a request for a client profile. Knime Server 4.13.4+ Fix from $1,9502021-12-08 MEDIUM 6.1 CVE-2021-44726 KNIME Server before 4.13.4 allows XSS via the old WebPortal login page. Knime Server 4.13.4+ Fix from $1,6002021-12-08