CWE-20 输入验证不恰当 类弱点 3596 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-20 属于输入验证不当漏洞,指软件接收数据时未正确校验其是否符合安全处理要求。攻击者常通过注入恶意或畸形数据,绕过逻辑检查以触发缓冲区溢出、命令执行等严重后果。开发者应实施严格的白名单验证,确保输入格式、类型及范围完全符合预期,并在所有数据入口点强制执行校验逻辑,从而从源头阻断潜在攻击。
... public static final double price = 20.00; int quantity = currentUser.getAttribute("quantity"); double total = price * quantity; chargeUser(total); ...... #define MAX_DIM 100 ... /* board dimensions */ int m,n, error; board_square_t *board; printf("Please specify the board height: \n"); error = scanf("%d", &m); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } printf("Please specify the board width: \n"); error = scanf("%d", &n); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } if ( m > MAX_DIM || n > MAX_DIM ) { die("Value too large: Die evil hacker!\n"); } board = (board_square_t*) malloc( m * n * sizeof(board_square_t)); ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2021-26630 | Handysoft Groupware 输入验证错误漏洞 — HANDY Groupware | 7.8 | High | 2022-05-19 |
| CVE-2022-1727 | JGraph draw.io输入验证错误漏洞 — jgraph/drawio | 8.8 | - | 2022-05-18 |
| CVE-2022-28190 | NVIDIA GPU Display Driver 输入验证错误漏洞 — NVIDIA GPU Display Driver | 5.5 | Medium | 2022-05-17 |
| CVE-2022-28188 | NVIDIA GPU Display Driver 输入验证错误漏洞 — NVIDIA GPU Display Driver | 5.5 | Medium | 2022-05-17 |
| CVE-2022-28186 | NVIDIA GPU Display Driver 输入验证错误漏洞 — NVIDIA GPU Display Driver | 6.1 | Medium | 2022-05-17 |
| CVE-2022-26782 | InHand Networks InRouter Series 缓冲区错误漏洞 — InRouter302 | 8.8 | - | 2022-05-12 |
| CVE-2022-26781 | InHand Networks InRouter Series 缓冲区错误漏洞 — InRouter302 | 8.8 | - | 2022-05-12 |
| CVE-2022-26780 | InHand Networks InRouter302 输入验证错误漏洞 — InRouter302 | 8.8 | - | 2022-05-12 |
| CVE-2022-29613 | SAP Employee Self Service 输入验证错误漏洞 — SAP Employee Self Service (Fiori My Leave Request) | 4.3 | - | 2022-05-11 |
| CVE-2022-29897 | PHOENIX CONTACT RAD-ISM-900-EN-* 输入验证错误漏洞 — RAD-ISM-900-EN-BD/B | 9.1 | Critical | 2022-05-11 |
| CVE-2021-46771 | AMD Secure Processor 安全漏洞 — 3rd Gen AMD EPYC™ | 7.8 | - | 2022-05-10 |
| CVE-2021-26370 | AMD EPYC UApp/ABL 输入验证错误漏洞 — 2nd Gen AMD EPYC™ | 7.1 | - | 2022-05-10 |
| CVE-2021-27760 | HCL Technologies Notes 安全漏洞 — HCL Notes | 4.6 | Medium | 2022-05-06 |
| CVE-2022-24098 | Adobe Photoshop 输入验证错误漏洞 — Photoshop | 7.8 | - | 2022-05-06 |
| CVE-2022-1053 | Keylime 输入验证错误漏洞 — keylime | 9.1 | - | 2022-05-06 |
| CVE-2022-26889 | Splunk 路径遍历漏洞 — Splunk Enterprise | 8.8 | High | 2022-05-06 |
| CVE-2021-25746 | Kubernetes ingress-nginx 输入验证错误漏洞 — Kubernetes ingress-nginx | 7.6 | High | 2022-05-06 |
| CVE-2021-25745 | Kubernetes ingress-nginx 输入验证错误漏洞 — Kubernetes ingress-nginx | 7.6 | High | 2022-05-06 |
| CVE-2022-29479 | F5 BIG-IP 输入验证错误漏洞 — BIG-IP | 5.3 | Medium | 2022-05-05 |
| CVE-2022-28708 | F5 BIG-IP 输入验证错误漏洞 — BIG-IP | 5.9 | Medium | 2022-05-05 |
| CVE-2022-28695 | F5 BIG-IP AFM 代码问题漏洞 — BIG-IP AFM | 7.2 | High | 2022-05-05 |
| CVE-2022-27634 | F5 BIG-IP APM 输入验证错误漏洞 — BIG-IP APM | 6.5 | Medium | 2022-05-05 |
| CVE-2022-28791 | Samsung Galaxy Store输入验证错误漏洞 — Galaxy Store | 6.2 | Medium | 2022-05-03 |
| CVE-2022-28783 | Samsung SMR 输入验证错误漏洞 — Samsung Mobile Devices | 6.2 | Medium | 2022-05-03 |
| CVE-2022-28781 | Samsung SMR 输入验证错误漏洞 — Samsung Mobile Devices | 7.7 | High | 2022-05-03 |
| CVE-2022-20745 | 多款Cisco产品输入验证错误漏洞 — Cisco Adaptive Security Appliance (ASA) Software | 8.6 | High | 2022-05-03 |
| CVE-2022-28196 | NVIDIA Jetson 缓冲区错误漏洞 — Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 NX, Jetson TX2 series | 4.6 | Medium | 2022-04-27 |
| CVE-2022-28195 | NVIDIA Jetson 输入验证错误漏洞 — Jetson AGX Xavier series, Jetson Xavier NX | 5.7 | Medium | 2022-04-27 |
| CVE-2022-28193 | NVIDIA Jetson 缓冲区错误漏洞 — Jetson AGX Xavier series, Jetson Xavier NX | 5.6 | Medium | 2022-04-27 |
| CVE-2022-1108 | Lenovo ThinkPad 缓冲区错误漏洞 — ThinkPad BIOS | 6.7 | Medium | 2022-04-22 |
CWE-20(输入验证不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 3596 条 CVE 漏洞。