Origin Validation Error | |
Arbitrary File Upload | |
Allocation of Resources Without Limits or Throttling | |
Path Equivalence | |
Open Redirect | |
Denial of Service (DoS) | |
Undefined Behavior for Input to API | |
Regular Expression Denial of Service (ReDoS) | |
Arbitrary File Write via Archive Extraction (Zip Slip) | |
Regular Expression Denial of Service (ReDoS) | |
Improper Handling of Case Sensitivity | |
Directory Traversal | |
Server-side Request Forgery (SSRF) | |
Race Condition | |
Directory Traversal | |
Origin Validation Error | |
Timing Attack | |
Always-Incorrect Control Flow Implementation | |
Origin Validation Error | |
Directory Traversal | |
Race Condition | |
Directory Traversal | |
Cross-site Scripting (XSS) | |
Server-side Request Forgery (SSRF) | |
Resources Downloaded over Insecure Protocol | |
Improper Input Validation | |
Missing Encryption of Sensitive Data | |
Arbitrary Code Injection | |
Open Redirect | |
Server-Side Request Forgery (SSRF) | |
Directory Traversal | |
Improper Access Control | |
Credential Exposure | |
Server-side Request Forgery (SSRF) | |
Improper Access Control | |
Directory Traversal | |
Race Condition | |
Improper Command Line Parameter Handling | |
Server-Side Request Forgery (SSRF) | |
Cross-Site Request Forgery (CSRF) | |
Arbitrary Command Injection | |
Timing Attack | |
Directory Traversal | |
Server-side Request Forgery (SSRF) | |
Server-side Request Forgery (SSRF) | |
Improper Input Validation | |
Use of Hard-coded Credentials | |
Improper Neutralization of Formula Elements in a CSV File | |
Arbitrary File Read | |
Arbitrary File Read | |