| Incorrect Implementation of Authentication Algorithm | |
| External Control of System or Configuration Setting | |
| Reliance on Untrusted Inputs in a Security Decision | |
| Inappropriate Encoding for Output Context | |
| Incomplete Blacklist | |
| Use of a Risky Cryptographic Primitive | |
| File and Directory Information Exposure | |
| Open Redirect | |
| Incorrect Implementation of Authentication Algorithm | |
| HTTP Request Smuggling | |
| Improper Input Validation | |
| Improper Certificate Validation | |
| Improper Validation of Unsafe Equivalence in Input | |
| Directory Traversal | |
| Improper Resource Shutdown or Release | |
| Improper Neutralization | |
| Session Fixation | |
| Resource Exhaustion | |
| Integer Overflow or Wraparound | |
| Race Condition | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Authentication Bypass | |
| Time-of-check Time-of-use (TOCTOU) | |
| Improper Handling of Case Sensitivity | |
| Improper Input Validation | |
| Improper Neutralization | |
| Path Equivalence | |
| Resource Exhaustion | |
| Time-of-check Time-of-use (TOCTOU) | |
| Uncaught Exception | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Incomplete Cleanup | |
| Improper Input Validation | |
| HTTP Request Smuggling | |
| Incomplete Cleanup | |
| Incomplete Cleanup | |
| Improper Input Validation | |
| Resource Exhaustion | |
| Open Redirect | |
| Off-by-one Error | |
| Information Exposure | |
| Allocation of Resources Without Limits or Throttling | |
| Arbitrary Code Injection | |