| Resource Exhaustion | |
| Incomplete Documentation | |
| Improper Handling of URL Encoding (Hex Encoding) | |
| Missing Critical Step in Authentication | |
| Improper Authorization | |
| Improper Authentication | |
| Always-Incorrect Control Flow Implementation | |
| Detection of Error Condition Without Action | |
| Always-Incorrect Control Flow Implementation | |
| Cross-site Scripting (XSS) | |
| Improper Authorization | |
| Information Exposure | |
| Improper Handling of Case Sensitivity | |
| Authentication Bypass | |
| Information Exposure | |
| Improper Input Validation | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-34500 | |
| Information Exposure Through Log Files | |
| Improper Encoding or Escaping of Output | |
| Improper Input Validation | |
| CVE-2026-29146 | |
| CVE-2026-29145 | |
| CVE-2026-29129 | |
| Open Redirect | |
| HTTP Request Smuggling | |
| CVE-2026-24734 | |
| CVE-2026-24733 | |
| Improper Certificate Validation | |
| Improper Resource Shutdown or Release | |
| Improper Neutralization | |
| Directory Traversal | |
| Session Fixation | |
| Resource Exhaustion | |
| Integer Overflow or Wraparound | |
| Race Condition | |
| Authentication Bypass | |
| Improper Resource Shutdown or Release | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2025-48976 | |
| Improper Handling of Case Sensitivity | |
| Improper Encoding or Escaping of Output | |
| Incomplete Cleanup | |
| Deserialization of Untrusted Data | |
| Time-of-check Time-of-use (TOCTOU) | |
| Resource Exhaustion | |
| Improper Check for Unusual or Exceptional Conditions | |
| Time-of-check Time-of-use (TOCTOU) | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| CVE-2024-24549 | |
| Incomplete Cleanup | |
| Information Exposure | |
| HTTP Request Smuggling | |
| Improper Input Validation | |
| CVE-2023-44487 | |
| Incomplete Cleanup | |
| Open Redirect | |
| Unprotected Transport of Credentials | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Encoding or Escaping of Output | |
| HTTP Request Smuggling | |
| Cross-site Scripting (XSS) | |
| Resource Exhaustion | |
| Improper Resource Shutdown or Release | |
| Time-of-check Time-of-use (TOCTOU) | |
| Race Condition | |
| Missing Release of Resource after Effective Lifetime | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| HTTP Request Smuggling | |
| Improper Encoding or Escaping of Output | |
| CVE-2021-25329 | |
| Information Exposure | |
| Use of Incorrectly-Resolved Name or Reference | |
| Information Exposure | |
| CVE-2020-13943 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Memory Leak | |
| CVE-2020-11996 | |
| HTTP Request Smuggling | |
| Session Fixation | |
| CVE-2019-12418 | |
| Improper Locking | |
| Deserialization of Untrusted Data | |
| CVE-2020-1938 | |
| HTTP Request Smuggling | |
| Cross-site Scripting (XSS) | |
| Resource Exhaustion | |