CWE-20 输入验证不恰当 类弱点 3418 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-20 属于输入验证不当漏洞,指软件接收数据时未正确校验其是否符合安全处理要求。攻击者常通过注入恶意或畸形数据,绕过逻辑检查以触发缓冲区溢出、命令执行等严重后果。开发者应实施严格的白名单验证,确保输入格式、类型及范围完全符合预期,并在所有数据入口点强制执行校验逻辑,从而从源头阻断潜在攻击。
... public static final double price = 20.00; int quantity = currentUser.getAttribute("quantity"); double total = price * quantity; chargeUser(total); ...... #define MAX_DIM 100 ... /* board dimensions */ int m,n, error; board_square_t *board; printf("Please specify the board height: \n"); error = scanf("%d", &m); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } printf("Please specify the board width: \n"); error = scanf("%d", &n); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } if ( m > MAX_DIM || n > MAX_DIM ) { die("Value too large: Die evil hacker!\n"); } board = (board_square_t*) malloc( m * n * sizeof(board_square_t)); ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-26293 | Siemens TIA Portal 输入验证错误漏洞 — Totally Integrated Automation Portal (TIA Portal) V15 | 7.3 | High | 2023-04-11 |
| CVE-2023-28710 | Apache Airflow 输入验证错误漏洞 — Apache Airflow Spark Provider | - | - | 2023-04-07 |
| CVE-2023-28707 | Apache Airflow 输入验证错误漏洞 — Apache Airflow Drill Provider | - | - | 2023-04-07 |
| CVE-2023-20103 | Cisco Secure Network Analytics 输入验证错误漏洞 — Cisco Secure Network Analytics | 4.9 | Medium | 2023-04-05 |
| CVE-2023-20132 | Cisco Webex Meetings 跨站脚本漏洞 — Cisco Webex Meetings | 5.4 | Medium | 2023-04-05 |
| CVE-2023-20134 | Cisco Webex Meetings 代码问题漏洞 — Cisco Webex Meetings | 5.4 | Medium | 2023-04-05 |
| CVE-2023-27496 | Envoy 输入验证错误漏洞 — envoy | 6.5 | Medium | 2023-04-04 |
| CVE-2023-27493 | Envoy 环境问题漏洞 — envoy | 8.1 | High | 2023-04-04 |
| CVE-2023-27491 | Envoy 环境问题漏洞 — envoy | 5.4 | Medium | 2023-04-04 |
| CVE-2023-27488 | Envoy 输入验证错误漏洞 — envoy | 5.4 | Medium | 2023-04-04 |
| CVE-2023-27487 | Envoy 输入验证错误漏洞 — envoy | 8.2 | High | 2023-04-04 |
| CVE-2022-33211 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 9.8 | Critical | 2023-04-04 |
| CVE-2023-1789 | firefly-iii 输入验证错误漏洞 — firefly-iii/firefly-iii | 9.1 | - | 2023-04-01 |
| CVE-2022-47188 | Generex UPS Adapter CS141 后置链接漏洞 — UPS CS141 | 7.5 | High | 2023-03-31 |
| CVE-2022-47189 | Generex UPS Adapter CS141 安全漏洞 — UPS CS141 | 7.5 | High | 2023-03-31 |
| CVE-2022-47190 | Generex UPS CS141 代码问题漏洞 — UPS CS141 | 10.0 | Critical | 2023-03-31 |
| CVE-2022-47191 | Generex UPS CS141 代码问题漏洞 — UPS CS141 | 4.3 | Medium | 2023-03-31 |
| CVE-2022-47192 | Generex UPS Adapter CS141 安全漏洞 — UPS CS141 | 8.8 | High | 2023-03-31 |
| CVE-2023-28733 | Acyba AcyMailing 跨站脚本漏洞 — Newsletter Plugin for Joomla in the Enterprise version | 7.2 | High | 2023-03-30 |
| CVE-2023-28732 | AcyMailing Joomla Component 路径遍历漏洞 — Newsletter Plugin for Joomla | 6.5 | Medium | 2023-03-30 |
| CVE-2023-28731 | Acyba AcyMailing 代码问题漏洞 — Newsletter Plugin for Joomla in the Enterprise version | 9.8 | Critical | 2023-03-30 |
| CVE-2023-0775 | Gecko SDK 安全漏洞 — GSDK | 6.5 | Medium | 2023-03-28 |
| CVE-2023-25879 | Adobe Dimension 输入验证错误漏洞 — Dimension | 7.8 | High | 2023-03-28 |
| CVE-2023-25881 | Adobe Dimension 输入验证错误漏洞 — Dimension | 7.8 | High | 2023-03-28 |
| CVE-2023-25901 | Adobe Dimension 输入验证错误漏洞 — Dimension | 7.8 | High | 2023-03-28 |
| CVE-2023-25661 | TensorFlow 输入验证错误漏洞 — tensorflow | 6.5 | Medium | 2023-03-27 |
| CVE-2022-47924 | Secvisogram 输入验证错误漏洞 — csaf-validator-lib | 6.5 | Medium | 2023-03-27 |
| CVE-2022-47925 | Secvisogram csaf-validator-service 输入验证错误漏洞 — csaf-validator-service | 7.5 | High | 2023-03-27 |
| CVE-2023-25865 | Adobe Substance 3D Stager 输入验证错误漏洞 — Substance3D - Stager | 7.8 | High | 2023-03-27 |
| CVE-2023-25867 | Adobe Substance 3D Stager 输入验证错误漏洞 — Substance3D - Stager | 7.8 | High | 2023-03-27 |
CWE-20(输入验证不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 3418 条 CVE 漏洞。