| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Encoding or Escaping of Output | |
| Allocation of Resources Without Limits or Throttling | |
| Arbitrary Code Injection | |
| Deserialization of Untrusted Data | |
| Allocation of Resources Without Limits or Throttling | |
| Deserialization of Untrusted Data | |
| Authentication Bypass | |
| Stack-based Buffer Overflow | |
| Link Following | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Validation of Specified Type of Input | |
| Insufficient Verification of Data Authenticity | |
| LDAP Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Incorrect Implementation of Authentication Algorithm | |
| Resource Exhaustion | |
| Link Following | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | |
| Out-of-bounds Read | |
| HTTP Request Smuggling | |
| Inadequate Encryption Strength | |
| Link Following | |
| External Control of File Name or Path | |
| Untrusted Search Path | |
| CVE-2025-24070 | |
| CVE-2024-43499 | |
| CVE-2024-43498 | |
| CVE-2024-43485 | |
| CVE-2024-43484 | |
| CVE-2024-43483 | |
| CVE-2024-38229 | |
| CVE-2024-38167 | |
| CVE-2024-38095 | |
| CVE-2024-35264 | |
| CVE-2024-30105 | |
| Race Condition | |
| CVE-2024-30045 | |
| CVE-2024-21392 | |
| CVE-2024-21404 | |
| CVE-2024-21386 | |
| CVE-2024-21319 | |
| CVE-2024-0057 | |
| CVE-2024-0056 | |
| CVE-2023-36558 | |
| CVE-2023-36049 | |
| CVE-2023-44487 | |
| CVE-2023-36799 | |
| CVE-2023-38180 | |
| CVE-2023-35390 | |
| Race Condition | |
| CVE-2023-33128 | |
| CVE-2023-32032 | |
| CVE-2023-29337 | |
| CVE-2023-29331 | |
| CVE-2023-24936 | |
| CVE-2022-41032 | |
| CVE-2022-38013 | |
| CVE-2022-34716 | |