| Resource Exhaustion | |
| Authentication Bypass | |
| Missing Authorization | |
| Improper Synchronization | |
| Cross-site Scripting (XSS) | |
| CVE-2023-1387 | |
| Improper Preservation of Permissions | |
| Incorrect Authorization | |
| Authentication Bypass | |
| Missing Release of Resource after Effective Lifetime | |
| CVE-2022-27664 | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Exposure of Private Information ('Privacy Violation') | |
| Inefficient Regular Expression Complexity | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Resource Exhaustion | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Improper Authentication | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| CVE-2022-41723 | |
| Improper Authentication | |
| CVE-2022-39201 | |
| Information Exposure | |
| Improper Input Validation | |
| Insufficiently Protected Credentials | |
| Improper Verification of Cryptographic Signature | |
| Improper Preservation of Permissions | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Open Redirect | |
| Directory Traversal | |
| Authentication Bypass | |
| Incorrect Authorization | |
| Incorrect Authorization | |
| NULL Pointer Dereference | |
| Cross-site Scripting (XSS) | |
| Buffer Overflow | |
| Directory Traversal | |
| Authorization Bypass Through User-Controlled Key | |
| Cross-site Scripting (XSS) | |
| Incorrect Authorization | |
| Cross-site Scripting (XSS) | |
| Cross-site Request Forgery (CSRF) | |