| Direct Request ('Forced Browsing') | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Incorrect Execution-Assigned Permissions | |
| Improper Handling of Inconsistent Special Elements | |
| Missing Release of Resource after Effective Lifetime | |
| Reversible One-Way Hash | |
| Information Exposure | |
| Uncaught Exception | |
| Allocation of Resources Without Limits or Throttling | |
| Inefficient Regular Expression Complexity | |
| Executable Regular Expression Error | |
| Allocation of Resources Without Limits or Throttling | |
| Reachable Assertion | |
| Allocation of Resources Without Limits or Throttling | |
| Inefficient Regular Expression Complexity | |
| Inefficient Regular Expression Complexity | |
| HTTP Request Smuggling | |
| OS Command Injection | |
| Uncaught Exception | |
| Allocation of Resources Without Limits or Throttling | |
| CRLF Injection | |
| Inefficient Regular Expression Complexity | |
| Uncaught Exception | |
| Allocation of Resources Without Limits or Throttling | |
| Directory Traversal | |
| Improper Preservation of Permissions | |
| Uncaught Exception | |
| Exposure of System Data to an Unauthorized Control Sphere | |
| Uncaught Exception | |
| Improper Preservation of Permissions | |
| Improper Preservation of Permissions | |
| Allocation of Resources Without Limits or Throttling | |
| Uncaught Exception | |
| Exposure of System Data to an Unauthorized Control Sphere | |
| Inefficient Regular Expression Complexity | |
| Memory Leak | |
| Uncaught Exception | |
| Resource Exhaustion | |
| Inefficient Regular Expression Complexity | |
| Use After Free | |