3600 vulnerabilities classified as CWE-20 (输入验证不恰当). AI Chinese analysis included.
CWE-20 represents a critical software weakness where applications fail to properly verify the integrity, format, or type of incoming data before processing it. This oversight allows attackers to inject malicious payloads, such as SQL injection strings or cross-site scripting code, which can bypass security controls and compromise system integrity. Exploitation typically occurs when untrusted data from external sources, like user forms or network packets, is treated as executable code or trusted input. To mitigate this risk, developers must implement rigorous input validation strategies, including strict type checking, length constraints, and allow-listing acceptable characters. Additionally, employing parameterized queries and output encoding ensures that even if validation fails, the injected data remains inert, thereby preserving application security and preventing unauthorized execution or data exposure.
... public static final double price = 20.00; int quantity = currentUser.getAttribute("quantity"); double total = price * quantity; chargeUser(total); ...... #define MAX_DIM 100 ... /* board dimensions */ int m,n, error; board_square_t *board; printf("Please specify the board height: \n"); error = scanf("%d", &m); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } printf("Please specify the board width: \n"); error = scanf("%d", &n); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } if ( m > MAX_DIM || n > MAX_DIM ) { die("Value too large: Die evil hacker!\n"); } board = (board_square_t*) malloc( m * n * sizeof(board_square_t)); ...| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2018-0373 | Cisco AnyConnect Secure Mobility Client for Windows Desktop 输入验证漏洞 — Cisco AnyConnect Secure Mobility Client unknown | 5.5 | - | 2018-06-21 |
| CVE-2018-0291 | 多款Cisco产品NX-OS Software Simple Network Management Protocol input packet processor 安全漏洞 — Cisco NX-OS unknown | 6.5 | - | 2018-06-20 |
| CVE-2018-0295 | 多款Cisco产品NX-OS Software 输入验证漏洞 — Cisco NX-OS unknown | 7.5 | - | 2018-06-20 |
| CVE-2018-0301 | 多款Cisco产品NX-OS Software 输入验证漏洞 — Cisco NX-OS unknown | 9.8 | - | 2018-06-20 |
| CVE-2018-0304 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件输入验证漏洞 — Cisco FXOS and NX-OS unknown | 9.8 | - | 2018-06-20 |
| CVE-2018-0307 | 多款Cisco产品NX-OS Software CLI 输入验证错误漏洞 — Cisco NX-OS unknown | 6.7 | - | 2018-06-20 |
| CVE-2018-0308 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件输入验证漏洞 — Cisco FXOS and NX-OS unknown | 9.8 | - | 2018-06-20 |
| CVE-2018-0312 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件输入验证漏洞 — Cisco FXOS and NX-OS unknown | 9.8 | - | 2018-06-20 |
| CVE-2018-0314 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件输入验证漏洞 — Cisco FXOS and NX-OS unknown | 9.8 | - | 2018-06-20 |
| CVE-2018-1061 | Python 资源管理错误漏洞 — python | 7.5 | - | 2018-06-19 |
| CVE-2018-1060 | Python 资源管理错误漏洞 — python | 7.5 | - | 2018-06-18 |
| CVE-2018-1070 | routing 安全漏洞 — routing | 6.5 | - | 2018-06-12 |
| CVE-2018-0338 | Cisco Unified Computing System Software 输入验证错误漏洞 — Cisco Unified Computing System unknown | 7.8 | - | 2018-06-07 |
| CVE-2018-0355 | Cisco Unified Communications Manager 输入验证错误漏洞 — Cisco Unified Communications Manager unknown | 6.1 | - | 2018-06-07 |
| CVE-2018-0274 | Cisco Network Services Orchestrator CLI解析器输入验证漏洞 — Cisco Network Services Orchestrator unknown | 8.8 | - | 2018-06-07 |
| CVE-2018-0296 | 多款Cisco产品ASA Software和Firepower Threat Defense Software 输入验证错误漏洞 — Cisco Adaptive Security Appliance unknown | 7.5 | - | 2018-06-07 |
| CVE-2017-16226 | The static-eval 输入验证错误漏洞 — static-eval node module node module | 9.8 | - | 2018-06-07 |
| CVE-2017-7653 | Eclipse Mosquitto broker 安全漏洞 — Eclipse Mosquitto | 7.5 | - | 2018-06-05 |
| CVE-2017-16005 | Http-signature 安全漏洞 — http-signature node module | 7.5 | - | 2018-06-04 |
| CVE-2016-10543 | call 安全漏洞 — call node module | 5.3 | - | 2018-05-31 |
| CVE-2016-10555 | jwt-simple 安全漏洞 — jwt-simple node module | 6.5 | - | 2018-05-31 |
| CVE-2015-9235 | jsonwebtoken node模块安全漏洞 — jsonwebtoken node module | 9.8 | - | 2018-05-29 |
| CVE-2017-2617 | hawtio 输入验证漏洞 — hawtio | 8.4 | - | 2018-05-22 |
| CVE-2018-8867 | 多款GE产品安全漏洞 — GE PACSystems RX3i CPE305/310 version 9.20 and prior RX3i CPE330 version 9.21 and prior RX3i CPE 400 version 9.30 and prior PACSystems RSTi-EP CPE 100 all versionsPACSystems CPU320/CRU320 RXi all versions | 7.5 | - | 2018-05-18 |
| CVE-2018-0279 | Cisco Enterprise NFV Infrastructure Software Secure Copy Protocol服务器输入验证错误漏洞 — Cisco Enterprise NFV Infrastructure Software | 8.8 | - | 2018-05-17 |
| CVE-2018-0280 | Cisco Meeting Server 输入验证漏洞 — Cisco Meeting Server Media Services | 7.5 | - | 2018-05-17 |
| CVE-2018-0325 | Cisco IP Phone 7800 Series和Cisco IP Phone 8800 Series 输入验证漏洞 — Cisco IP Phone 7800 Series and 8800 Series | 7.5 | - | 2018-05-17 |
| CVE-2018-4850 | Siemens SIMATIC S7-400和SIMATIC S7-400H 安全漏洞 — SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below, SIMATIC S7-400 (incl. F) CPU hardware version 5.0, SIMATIC S7-400H CPU hardware version 4.5 and below | 7.5 | - | 2018-05-16 |
| CVE-2017-6021 | Schneider Electric ClearSCADA 安全漏洞 — ClearSCADA | 7.5 | - | 2018-05-14 |
| CVE-2018-8869 | Lantech IDS 2102 输入验证漏洞 — IDS 2102 | 9.8 | - | 2018-05-04 |
Vulnerabilities classified as CWE-20 (输入验证不恰当) represent 3600 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.