| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Out-of-bounds Write | |
| Improper Validation of Unsafe Equivalence in Input | |
| Improper Cross-boundary Removal of Sensitive Data | |
| Improper Validation of Specified Type of Input | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improper Validation of Specified Type of Input | |
| Out-of-bounds Read | |
| Uncontrolled Recursion | |
| Integer Overflow or Wraparound | |
| Improper Validation of Unsafe Equivalence in Input | |
| Incorrect Calculation of Buffer Size | |
| Time-of-check Time-of-use (TOCTOU) | |
| External Control of Assumed-Immutable Web Parameter | |
| Allocation of Resources Without Limits or Throttling | |
| Insufficient Granularity of Access Control | |
| Improper Handling of Length Parameter Inconsistency | |
| Improper Validation of Syntactic Correctness of Input | |
| Authorization Bypass Through User-Controlled Key | |
| HTTP Request Smuggling | |
| External Control of Assumed-Immutable Web Parameter | |
| Directory Traversal | |
| Allocation of Resources Without Limits or Throttling | |
| Exposure of System Data to an Unauthorized Control Sphere | |
| HTTP Request Smuggling | |
| CRLF Injection | |
| Improper Validation of Syntactic Correctness of Input | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Validation of Syntactic Correctness of Input | |
| Allocation of Resources Without Limits or Throttling | |
| Arbitrary Code Injection | |
| Improper Certificate Validation | |
| Inefficient Regular Expression Complexity | |
| Inefficient Regular Expression Complexity | |
| Creation of Temporary File in Directory with Incorrect Permissions | |
| Unchecked Input for Loop Condition | |
| Inefficient Regular Expression Complexity | |
| Buffer Access with Incorrect Length Value | |
| Cross-site Scripting (XSS) | |
| SQL Injection | |
| SQL Injection | |
| Time-of-check Time-of-use (TOCTOU) | |
| Cross-site Scripting (XSS) | |
| Directory Traversal | |
| Expression Language Injection | |
| Allocation of Resources Without Limits or Throttling | |
| SQL Injection | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Buffer Overflow | |
| Not Failing Securely ('Failing Open') | |
| Reachable Assertion | |
| Server-Side Request Forgery (SSRF) | |
| Improper Verification of Cryptographic Signature | |
| Server-Side Request Forgery (SSRF) | |
| Improper Validation of Integrity Check Value | |
| Open Redirect | |
| Improper Handling of Additional Special Element | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Incomplete Blacklist | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | |
| SQL Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Directory Traversal | |
| Reachable Assertion | |
| Improper Handling of Unexpected Data Type | |
| Allocation of Resources Without Limits or Throttling | |
| Use After Free | |
| Inefficient Regular Expression Complexity | |
| Origin Validation Error | |
| Exposed Dangerous Method or Function | |
| Directory Traversal | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Arbitrary Code Injection | |
| Resource Exhaustion | |
| Excessive Platform Resource Consumption within a Loop | |
| Information Exposure | |
| Always-Incorrect Control Flow Implementation | |
| Cross-site Scripting (XSS) | |
| Improper Check for Unusual or Exceptional Conditions | |
| Arbitrary Code Injection | |
| Information Exposure | |
| Cross-site Scripting (XSS) | |
| Server-Side Request Forgery (SSRF) | |
| Improper Access Control | |
| Path Equivalence | |
| Directory Traversal | |
| CVE-2024-45231 | |
| Inefficient Regular Expression Complexity | |
| Server-Side Request Forgery (SSRF) | |
| Insufficient Compartmentalization | |
| Inefficient Regular Expression Complexity | |
| Open Redirect | |
| Improper Cross-boundary Removal of Sensitive Data | |
| Cross-site Scripting (XSS) | |
| Improper Certificate Validation | |
| SQL Injection | |
| Allocation of Resources Without Limits or Throttling | |