| Path Equivalence | |
| HTTP Request Smuggling | |
| Information Exposure | |
| Incomplete Cleanup | |
| Improper Input Validation | |
| HTTP Request Smuggling | |
| Open Redirect | |
| Allocation of Resources Without Limits or Throttling | |
| Incomplete Cleanup | |
| Resource Exhaustion | |
| Improper Input Validation | |
| Off-by-one Error | |
| Race Condition | |
| Information Exposure | |
| Incomplete Documentation of Program Execution | |
| Sensitive Information Uncleared Before Release | |
| Time-of-check Time-of-use (TOCTOU) | |
| Improper Input Validation | |
| Missing Release of Resource after Effective Lifetime | |
| HTTP Request Smuggling | |
| Deserialization of Untrusted Data | |
| Information Exposure | |
| Information Exposure | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| NULL Pointer Dereference | |
| Deserialization of Untrusted Data | |
| Improper Privilege Management | |
| HTTP Request Smuggling | |
| HTTP Request Smuggling | |
| CVE-2019-12418 | |
| Session Fixation | |
| OS Command Injection | |
| Cross-site Scripting (XSS) | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Open Redirect | |
| Race Condition | |
| Insecure Default Initialization of Resource | |
| Improper Certificate Validation | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| CVE-2018-1305 | |
| CVE-2018-1304 | |
| Improperly Implemented Security Check for Standard | |
| Unrestricted Upload of File with Dangerous Type | |
| Insufficient Verification of Data Authenticity | |
| Improper Handling of Exceptional Conditions | |
| Insufficient Verification of Data Authenticity | |
| Improper Handling of Exceptional Conditions | |
| Information Exposure | |
| Exposure of Resource to Wrong Sphere | |
| Error Handling | |
| Improper Input Validation | |
| Improper Access Control | |
| Security Features | |
| Improper Access Control | |
| Access Restriction Bypass | |
| Information Exposure | |
| Access Restriction Bypass | |
| Security Features | |
| Improper Input Validation | |
| Improper Input Validation | |
| Access Restriction Bypass | |
| Information Exposure | |
| Access Restriction Bypass | |
| Cross-site Request Forgery (CSRF) | |
| CVE-2015-5346 | |
| Directory Traversal | |
| Directory Traversal | |
| Improper Access Control | |
| Improper Data Handling | |
| Numeric Errors | |
| Access Restriction Bypass | |
| Numeric Errors | |