| Directory Traversal | |
| Use of a Broken or Risky Cryptographic Algorithm | |
| Improper Verification of Cryptographic Signature | |
| Permissive Cross-domain Policy with Untrusted Domains | |
| Incorrect Authorization | |
| Use of Cache Containing Sensitive Information | |
| Cross-site Scripting (XSS) | |
| Incorrect Regular Expression | |
| Unverified Ownership | |
| Directory Traversal | |
| HTTP Request Smuggling | |
| Asymmetric Resource Consumption (Amplification) | |
| Arbitrary Code Injection | |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| Improper Control of Generation of Code ('Code Injection') | |
| Cross-Site Request Forgery (CSRF) | |
| Cross-site Request Forgery (CSRF) | |
| Use of Incorrectly-Resolved Name or Reference | |
| HTTP Request Smuggling | |
| Allocation of Resources Without Limits or Throttling | |
| Race Condition | |
| Improperly Implemented Security Check for Standard | |
| Improper Encoding or Escaping of Output | |
| HTTP Response Splitting | |
| Cross-site Scripting (XSS) | |
| HTTP Request Smuggling | |
| Cross-site Scripting (XSS) | |
| Use of Less Trusted Source | |
| Prototype Pollution | |
| Timing Attack | |
| Regular Expression Denial of Service (ReDoS) | |
| Exposure of Data Element to Wrong Session | |
| HTTP Request Smuggling | |
| Inefficient Algorithmic Complexity | |
| User Impersonation | |
| CRLF Injection | |
| CRLF Injection | |
| Directory Traversal | |
| Improper Input Validation | |
| Directory Traversal | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| Improper Handling of URL Encoding (Hex Encoding) | |
| Improper Encoding or Escaping of Output | |
| Improper Validation of Specified Quantity in Input | |
| Use of Cache Containing Sensitive Information | |
| HTML Injection | |
| HTTP Request Smuggling | |
| Improper Authorization | |
| HTTP Response Splitting | |
| Incorrect Regular Expression | |
| Insufficient Verification of Data Authenticity | |