CWE-20 输入验证不恰当 类弱点 3590 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-20 属于输入验证不当漏洞,指软件接收数据时未正确校验其是否符合安全处理要求。攻击者常通过注入恶意或畸形数据,绕过逻辑检查以触发缓冲区溢出、命令执行等严重后果。开发者应实施严格的白名单验证,确保输入格式、类型及范围完全符合预期,并在所有数据入口点强制执行校验逻辑,从而从源头阻断潜在攻击。
... public static final double price = 20.00; int quantity = currentUser.getAttribute("quantity"); double total = price * quantity; chargeUser(total); ...... #define MAX_DIM 100 ... /* board dimensions */ int m,n, error; board_square_t *board; printf("Please specify the board height: \n"); error = scanf("%d", &m); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } printf("Please specify the board width: \n"); error = scanf("%d", &n); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } if ( m > MAX_DIM || n > MAX_DIM ) { die("Value too large: Die evil hacker!\n"); } board = (board_square_t*) malloc( m * n * sizeof(board_square_t)); ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-1250 | OTRS 代码注入漏洞 — OTRS | 7.4 | High | 2023-03-20 |
| CVE-2023-28100 | Flatpak 输入验证错误漏洞 — flatpak | 10.0 | Critical | 2023-03-16 |
| CVE-2023-24571 | Dell BIOS 输入验证错误漏洞 — Embedded Box PC 3000 , CPG BIOS | 7.5 | High | 2023-03-16 |
| CVE-2023-21453 | SAMSUNG Mobile Devices 输入验证错误漏洞 — Samsung Mobile Devices | 6.0 | Medium | 2023-03-16 |
| CVE-2023-28113 | russh 数据伪造问题漏洞 — russh | 5.9 | Medium | 2023-03-16 |
| CVE-2023-28099 | OpenSIPS 输入验证错误漏洞 — opensips | 5.9 | Medium | 2023-03-15 |
| CVE-2023-28098 | OpenSIPS 输入验证错误漏洞 — opensips | 5.9 | Medium | 2023-03-15 |
| CVE-2023-28095 | OpenSIPS 输入验证错误漏洞 — opensips | 7.5 | High | 2023-03-15 |
| CVE-2023-27601 | OpenSIPS 输入验证错误漏洞 — opensips | 7.5 | High | 2023-03-15 |
| CVE-2023-27600 | OpenSIPS 输入验证错误漏洞 — opensips | 7.5 | High | 2023-03-15 |
| CVE-2023-27599 | OpenSIPS 输入验证错误漏洞 — opensips | 7.5 | High | 2023-03-15 |
| CVE-2023-27597 | OpenSIPS 输入验证错误漏洞 — opensips | 7.5 | High | 2023-03-15 |
| CVE-2023-0100 | Eclipse BIRT 安全漏洞 — Eclipse BIRT (Business Intelligence Reporting Tool) | 9.1 | - | 2023-03-15 |
| CVE-2023-24866 | Microsoft PostScript Printer Driver 安全漏洞 — Windows 10 Version 1809 | 6.5 | Medium | 2023-03-14 |
| CVE-2023-24865 | Microsoft PostScript Printer Driver 安全漏洞 — Windows 10 Version 1809 | 6.5 | Medium | 2023-03-14 |
| CVE-2023-23419 | Microsoft Windows Resilient File System (ReFS) 安全漏洞 — Windows 11 version 22H2 | 7.8 | High | 2023-03-14 |
| CVE-2023-23416 | Microsoft Windows Cryptographic Services 安全漏洞 — Windows 10 Version 1809 | 7.8 | High | 2023-03-14 |
| CVE-2023-23409 | Microsoft Client Server Run-time Subsystem (CSRSS) 安全漏洞 — Windows 10 Version 1809 | 5.5 | Medium | 2023-03-14 |
| CVE-2023-24856 | Microsoft PostScript Printer Driver 安全漏洞 — Windows 10 Version 1809 | 7.5 | High | 2023-03-14 |
| CVE-2023-23397 | Microsoft Outlook 安全漏洞 — Microsoft Office LTSC 2021 | 9.8 | Critical | 2023-03-14 |
| CVE-2023-25947 | OpenHarmony 代码问题漏洞 — OpenHarmony | 6.2 | Medium | 2023-03-10 |
| CVE-2023-24465 | OpenHarmony 代码问题漏洞 — OpenHarmony | 5.5 | Medium | 2023-03-10 |
| CVE-2023-22301 | OpenHarmony 安全漏洞 — OpenHarmony | 6.5 | Medium | 2023-03-10 |
| CVE-2021-36402 | Moodle 输入验证错误漏洞 — Moodle | 4.3 | - | 2023-03-06 |
| CVE-2022-4904 | c-ares 输入验证错误漏洞 — c-ares | 8.6 | - | 2023-03-06 |
| CVE-2022-3294 | Kubernetes 安全漏洞 — Kubernetes | 6.6 | Medium | 2023-03-01 |
| CVE-2023-26281 | IBM WebSphere Application Server 输入验证错误漏洞 — HTTP Server | 5.9 | Medium | 2023-02-28 |
| CVE-2022-40237 | IBM MQ 输入验证错误漏洞 — MQ for HPE NonStop | 6.5 | Medium | 2023-02-27 |
| CVE-2023-25696 | Apache Airflow 输入验证错误漏洞 — Apache Airflow Hive Provider | 7.5 | - | 2023-02-24 |
| CVE-2023-25693 | Apache Airflow 输入验证错误漏洞 — Apache Airflow Sqoop Provider | 9.1 | - | 2023-02-24 |
CWE-20(输入验证不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 3590 条 CVE 漏洞。