CWE-20 输入验证不恰当 类弱点 3594 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-20 属于输入验证不当漏洞,指软件接收数据时未正确校验其是否符合安全处理要求。攻击者常通过注入恶意或畸形数据,绕过逻辑检查以触发缓冲区溢出、命令执行等严重后果。开发者应实施严格的白名单验证,确保输入格式、类型及范围完全符合预期,并在所有数据入口点强制执行校验逻辑,从而从源头阻断潜在攻击。
... public static final double price = 20.00; int quantity = currentUser.getAttribute("quantity"); double total = price * quantity; chargeUser(total); ...... #define MAX_DIM 100 ... /* board dimensions */ int m,n, error; board_square_t *board; printf("Please specify the board height: \n"); error = scanf("%d", &m); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } printf("Please specify the board width: \n"); error = scanf("%d", &n); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } if ( m > MAX_DIM || n > MAX_DIM ) { die("Value too large: Die evil hacker!\n"); } board = (board_square_t*) malloc( m * n * sizeof(board_square_t)); ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2022-36854 | SAMSUNG Mobile devices 缓冲区错误漏洞 — Samsung Mobile Devices | 4.0 | Medium | 2022-09-09 |
| CVE-2022-36859 | SAMSUNG Mobile devices 跨站脚本漏洞 — SmartTagPlugin | 5.7 | Medium | 2022-09-09 |
| CVE-2022-3169 | RISC-V 输入验证错误漏洞 — Kernel | 5.5 | - | 2022-09-09 |
| CVE-2022-36087 | OAuthLib 输入验证错误漏洞 — oauthlib | 5.7 | Medium | 2022-09-09 |
| CVE-2022-36082 | mangadex-downloader 输入验证错误漏洞 — mangadex-downloader | 5.3 | Medium | 2022-09-07 |
| CVE-2022-36058 | Elrond go 输入验证错误漏洞 — elrond-go | 7.5 | High | 2022-09-06 |
| CVE-2022-36032 | ReactPHP HTTP 安全漏洞 — http | 5.3 | Medium | 2022-09-06 |
| CVE-2021-3754 | Red Hat Keycloak 安全漏洞 — keycloak | 5.3 | - | 2022-08-26 |
| CVE-2021-4041 | Ansible-Runner 操作系统命令注入漏洞 — ansible-runner | 7.8 | - | 2022-08-24 |
| CVE-2021-4125 | Red Hat OpenShift 代码问题漏洞 — kube-reporting/hive | 8.1 | - | 2022-08-24 |
| CVE-2021-4204 | Linux kernel 缓冲区错误漏洞 — kernel | 6.0 | - | 2022-08-24 |
| CVE-2020-35509 | Red Hat Keycloak 信任管理问题漏洞 — keycloak | 5.9 | - | 2022-08-23 |
| CVE-2021-3442 | Red Hat 3scale API Management Platform 输入验证错误漏洞 — Red Hat OpenShift API Management. | 5.4 | - | 2022-08-22 |
| CVE-2022-34916 | Apache Flume 输入验证错误漏洞 — Apache Flume | 9.8 | - | 2022-08-21 |
| CVE-2022-36023 | Hyperledger Fabric 输入验证错误漏洞 — fabric | 7.0 | High | 2022-08-18 |
| CVE-2022-2868 | LibTIFF 缓冲区错误漏洞 — libtiff | 5.5 | - | 2022-08-17 |
| CVE-2020-1756 | Moodle 输入验证错误漏洞 — Moodle | 6.7 | - | 2022-08-16 |
| CVE-2022-24952 | Eternal Terminal 输入验证错误漏洞 — Eternal Terminal | 6.5 | - | 2022-08-16 |
| CVE-2021-22289 | B&R Automation Studio 输入验证错误漏洞 — Automation Studio | 8.3 | High | 2022-08-11 |
| CVE-2022-28755 | Zoom Client 输入验证错误漏洞 — Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) | 9.6 | Critical | 2022-08-11 |
| CVE-2022-35666 | Adobe Acrobat Reader 输入验证错误漏洞 — Acrobat Reader | 7.8 | High | 2022-08-11 |
| CVE-2022-35668 | Adobe Acrobat Reader输入验证错误漏洞 — Acrobat Reader | 5.5 | Medium | 2022-08-11 |
| CVE-2022-31779 | Apache Traffic Server 输入验证错误漏洞 — Apache Traffic Server | 7.5 | - | 2022-08-10 |
| CVE-2021-37150 | Apache Traffic Server 输入验证错误漏洞 — Apache Traffic Server | 7.5 | - | 2022-08-10 |
| CVE-2022-28129 | Apache Traffic Server 输入验证错误漏洞 — Apache Traffic Server | 7.5 | - | 2022-08-10 |
| CVE-2022-31778 | Apache Traffic Server 输入验证错误漏洞 — Apache Traffic Server | 7.5 | - | 2022-08-10 |
| CVE-2022-31780 | Apache Traffic Server 输入验证错误漏洞 — Apache Traffic Server | 7.5 | - | 2022-08-10 |
| CVE-2022-36125 | Apache Avro 输入验证错误漏洞 — Apache Avro | 7.5 | - | 2022-08-09 |
| CVE-2022-35724 | Apache Avro 安全漏洞 — Apache Avro | 7.5 | - | 2022-08-09 |
| CVE-2022-33719 | SAMSUNG Mobile devices 输入验证错误漏洞 — Samsung Mobile Devices | 8.6 | High | 2022-08-05 |
CWE-20(输入验证不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 3594 条 CVE 漏洞。