Cwe 20

CWE-20: 入力検証の不備 🧬 CWE 関連 125
slug: cwe-20

解説

CWE-20は「ユーザーから受け取ったデータが、想定された形式・範囲・型かをきちんとチェックせずに使ってしまう欠陥」のことです。 非常に広い概念で、SQLi・XSS・コマンドインジェクションなど多くの攻撃の前段階となります。 「入力は信用するな (Trust Boundaries の概念)」がセキュリティ設計の基本原則です。
📌 具体例
多くのCISA KEV登録CVEがこのCWEに分類されており、2024年だけで100件以上の悪用事例があります。

🔖 関連タグ

🛡 このタグに関連する脆弱性 2,280

ID タイトル
CVE-2026-59881 aiohttp の脆弱性 (CVE-2026-59881)
CVE-2026-18014 google の脆弱性 (CVE-2026-18014)
CVE-2026-18009 google の脆弱性 (CVE-2026-18009)
CVE-2026-18002 google の脆弱性 (CVE-2026-18002)
CVE-2026-17988 google の脆弱性 (CVE-2026-17988)
CVE-2026-17990 google の脆弱性 (CVE-2026-17990)
CVE-2026-17987 google の脆弱性 (CVE-2026-17987)
CVE-2026-17991 google の脆弱性 (CVE-2026-17991)
CVE-2026-17982 google の脆弱性 (CVE-2026-17982)
CVE-2026-17970 google の脆弱性 (CVE-2026-17970)
CVE-2026-17955 google の脆弱性 (CVE-2026-17955)
CVE-2026-17940 google の脆弱性 (CVE-2026-17940)
CVE-2026-17939 google の脆弱性 (CVE-2026-17939)
CVE-2026-17937 google の脆弱性 (CVE-2026-17937)
CVE-2026-17929 google の脆弱性 (CVE-2026-17929)
CVE-2026-17930 privilege-escalation の脆弱性 (CVE-2026-17930)
CVE-2026-17934 google の脆弱性 (CVE-2026-17934)
CVE-2026-17921 google の脆弱性 (CVE-2026-17921)
CVE-2026-17926 google の脆弱性 (CVE-2026-17926)
CVE-2026-17909 google の脆弱性 (CVE-2026-17909)
CVE-2026-17908 google の脆弱性 (CVE-2026-17908)
CVE-2026-17901 google の脆弱性 (CVE-2026-17901)
CVE-2026-17906 google の脆弱性 (CVE-2026-17906)
CVE-2026-17893 google の脆弱性 (CVE-2026-17893)
CVE-2026-17888 google の脆弱性 (CVE-2026-17888)
CVE-2026-17890 google の脆弱性 (CVE-2026-17890)
CVE-2026-17867 google の脆弱性 (CVE-2026-17867)
CVE-2026-17870 google の脆弱性 (CVE-2026-17870)
CVE-2026-17860 c の脆弱性 (CVE-2026-17860)
CVE-2026-17861 privilege-escalation の脆弱性 (CVE-2026-17861)

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →