| Deserialization of Untrusted Data | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Reliance on Untrusted Inputs in a Security Decision | |
| Arbitrary Code Injection | |
| Improper Verification of Cryptographic Signature | |
| Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Validation of Specified Type of Input | |
| External Control of Assumed-Immutable Web Parameter | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Incorrect Implementation of Authentication Algorithm | |
| Buffer Overflow | |
| Link Following | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| CRLF Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Link Following | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Improper Neutralization of Special Elements | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| Out-of-bounds Write | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | |
| Insecure Temporary File | |
| Cleartext Transmission of Sensitive Information | |
| HTTP Request Smuggling | |
| Uncontrolled Search Path Element | |
| Authentication Bypass | |
| Improper Privilege Management | |
| Cross-site Scripting (XSS) | |
| Improper Restriction of Names for Files and Other Resources | |
| Creation of Temporary File in Directory with Incorrect Permissions | |
| Buffer Over-read | |
| Allocation of Resources Without Limits or Throttling | |
| Use After Free | |
| Algorithmic Complexity | |
| Algorithmic Complexity | |
| Information Exposure | |
| CVE-2024-38095 | |
| CVE-2024-35264 | |
| CVE-2024-30105 | |
| Deadlock | |
| Out-of-Bounds | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| CVE-2024-21386 | |
| Improper Certificate Validation | |
| Unprotected Alternate Channel | |
| Resource Exhaustion | |
| CVE-2023-36558 | |
| Arbitrary Code Injection | |