CWE-20 输入验证不恰当 类弱点 4213 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-20 属于输入验证不当漏洞,指软件接收数据时未正确校验其是否符合安全处理要求。攻击者常通过注入恶意或畸形数据,绕过逻辑检查以触发缓冲区溢出、命令执行等严重后果。开发者应实施严格的白名单验证,确保输入格式、类型及范围完全符合预期,并在所有数据入口点强制执行校验逻辑,从而从源头阻断潜在攻击。
... public static final double price = 20.00; int quantity = currentUser.getAttribute("quantity"); double total = price * quantity; chargeUser(total); ...
... #define MAX_DIM 100 ... /* board dimensions */ int m,n, error; board_square_t *board; printf("Please specify the board height: \n"); error = scanf("%d", &m); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } printf("Please specify the board width: \n"); error = scanf("%d", &n); if ( EOF == error ){ die("No integer passed: Die evil hacker!\n"); } if ( m > MAX_DIM || n > MAX_DIM ) { die("Value too large: Die evil hacker!\n"); } board = (board_square_t*) malloc( m * n * sizeof(board_square_t)); ...
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2017-7653 | Eclipse Mosquitto broker 安全漏洞 — Eclipse Mosquitto | 7.5 | - | 2018-06-05 |
| CVE-2017-16005 | Http-signature 安全漏洞 — http-signature node module | 7.5 | - | 2018-06-04 |
| CVE-2016-10543 | call 安全漏洞 — call node module | 5.3 | - | 2018-05-31 |
| CVE-2016-10555 | jwt-simple 安全漏洞 — jwt-simple node module | 6.5 | - | 2018-05-31 |
| CVE-2015-9235 | jsonwebtoken node模块安全漏洞 — jsonwebtoken node module | 9.8 | - | 2018-05-29 |
| CVE-2017-2617 | hawtio 输入验证漏洞 — hawtio | 8.4 | - | 2018-05-22 |
| CVE-2018-8867 | 多款GE产品安全漏洞 — GE PACSystems RX3i CPE305/310 version 9.20 and prior RX3i CPE330 version 9.21 and prior RX3i CPE 400 version 9.30 and prior PACSystems RSTi-EP CPE 100 all versionsPACSystems CPU320/CRU320 RXi all versions | 7.5 | - | 2018-05-18 |
| CVE-2018-0279 | Cisco Enterprise NFV Infrastructure Software Secure Copy Protocol服务器输入验证错误漏洞 — Cisco Enterprise NFV Infrastructure Software | 8.8 | - | 2018-05-17 |
| CVE-2018-0280 | Cisco Meeting Server 输入验证漏洞 — Cisco Meeting Server Media Services | 7.5 | - | 2018-05-17 |
| CVE-2018-0325 | Cisco IP Phone 7800 Series和Cisco IP Phone 8800 Series 输入验证漏洞 — Cisco IP Phone 7800 Series and 8800 Series | 7.5 | - | 2018-05-17 |
| CVE-2018-4850 | Siemens SIMATIC S7-400和SIMATIC S7-400H 安全漏洞 — SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below, SIMATIC S7-400 (incl. F) CPU hardware version 5.0, SIMATIC S7-400H CPU hardware version 4.5 and below | 7.5 | - | 2018-05-16 |
| CVE-2017-6021 | Schneider Electric ClearSCADA 安全漏洞 — ClearSCADA | 7.5 | - | 2018-05-14 |
| CVE-2018-8869 | Lantech IDS 2102 输入验证漏洞 — IDS 2102 | 9.8 | - | 2018-05-04 |
| CVE-2018-0234 | Cisco Aironet 1810、1830和1850 Series Access Points 输入验证漏洞 — Cisco Aironet 1810, 1830, and 1850 Series Access Points | 8.6 | - | 2018-05-02 |
| CVE-2018-0235 | Cisco Wireless LAN Controller 输入验证错误漏洞 — Cisco Wireless LAN Controller | 7.4 | - | 2018-05-02 |
| CVE-2018-0249 | 多款Cisco产品输入验证错误漏洞 — Cisco Aironet 1800 Series Access Point | 6.5 | - | 2018-05-02 |
| CVE-2018-0253 | Cisco Secure Access Control System ACS Report组件输入验证漏洞 — Cisco Secure Access Control System | 9.8 | - | 2018-05-02 |
| CVE-2018-0264 | Cisco WebEx Business Suite meeting sites、WebEx Meetings sites和WebEx Meetings Server 安全漏洞 — Cisco WebEx Advanced Recording Format file players | 9.6 | - | 2018-05-02 |
| CVE-2018-0287 | Cisco WebEx Business Suite meeting sites、WebEx Meetings sites和WebEx Meetings Server 输入验证漏洞 — Cisco WebEx Advanced Recording Format Player | 8.8 | - | 2018-05-02 |
| CVE-2018-1104 | Ansible Tower 安全漏洞 — Ansible Tower | 8.8 | - | 2018-05-02 |
| CVE-2018-6589 | CA Spectrum 安全漏洞 — CA Spectrum | 7.5 | - | 2018-05-01 |
| CVE-2018-1102 | Red Hat Openshift Enterprise 安全漏洞 — atomic-openshift | 8.8 | - | 2018-04-30 |
| CVE-2018-4832 | Siemens多款产品输入验证错误漏洞 — OpenPCS 7 V7.1 and earlier | 6.5 | - | 2018-04-24 |
| CVE-2016-9587 | Ansible 输入验证漏洞 — Ansible | 7.1 | - | 2018-04-24 |
| CVE-2018-0112 | 多款Cisco产品输入验证漏洞 — Cisco WebEx Clients | 8.0 | - | 2018-04-19 |
| CVE-2018-0228 | 多款Cisco产品Adaptive Security Appliance和Firepower Threat Defense Software 输入验证错误漏洞 — Cisco Adaptive Security Appliance | 8.6 | - | 2018-04-19 |
| CVE-2018-0231 | 多款Cisco产品缓冲区错误漏洞 — Cisco Adaptive Security Appliance | 8.6 | - | 2018-04-19 |
| CVE-2018-0237 | Cisco Advanced Malware Protection for Endpoints macOS Connector 输入验证错误漏洞 — Cisco AMP for Endpoints | 8.6 | - | 2018-04-19 |
| CVE-2018-0239 | Cisco Aggregation Services Router 5000 Series Routers和Virtualized Packet Core System Software StarOS 输入验证错误漏洞 — Cisco StarOS | 7.5 | - | 2018-04-19 |
| CVE-2018-0256 | Cisco Packet Data Network Gateway 输入验证漏洞 — Cisco Packet Data Network Gateway | 8.6 | - | 2018-04-19 |
CWE-20(输入验证不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 4213 条 CVE 漏洞。