| Uncaught Exception | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Cross-site Scripting (XSS) | |
| Incorrect Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| Link Following | |
| Unchecked Input for Loop Condition | |
| Function Call with Incorrectly Specified Arguments | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Inefficient Regular Expression Complexity | |
| Incorrectly Specified Destination in a Communication Channel | |
| External Initialization of Trusted Variables or Data Stores | |
| Incomplete Blacklist | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improper Validation of Specified Type of Input | |
| Server-Side Request Forgery (SSRF) | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Comparison of Incompatible Types | |
| Server-Side Request Forgery (SSRF) | |
| Uncaught Exception | |
| Allocation of Resources Without Limits or Throttling | |
| Incomplete Blacklist | |
| Inefficient Regular Expression Complexity | |
| Inefficient Regular Expression Complexity | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Validation of Specified Index, Position, or Offset in Input | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Inefficient Regular Expression Complexity | |
| Cross-site Scripting (XSS) | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure Through Caching | |
| Information Exposure Through Caching | |
| Allocation of Resources Without Limits or Throttling | |
| Privilege Defined With Unsafe Actions | |
| Authorization Bypass Through User-Controlled Key | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Use of a Non-reentrant Function in a Concurrent Context | |
| Least Privilege Violation | |
| Insufficient Granularity of Access Control | |
| Permissive Whitelist | |
| SQL Injection | |
| Improper Certificate Validation | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Cross-site Scripting (XSS) | |
| Operator Precedence Logic Error | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Improper Handling of Case Sensitivity | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Cross-site Scripting (XSS) | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Authorization Bypass Through User-Controlled Key | |
| Improper Validation of Specified Type of Input | |
| Improper Validation of Unsafe Equivalence in Input | |
| Improper Neutralization | |
| Allocation of Resources Without Limits or Throttling | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Missing Authentication for Critical Function | |
| HTTP Request Smuggling | |
| Improper Neutralization of Equivalent Special Elements | |
| Server-Side Request Forgery (SSRF) | |
| Improper Neutralization | |
| Numeric Range Comparison Without Minimum Check | |