| Denial of Service (DoS) | |
| Insufficient Verification of Data Authenticity | |
| Denial of Service (DoS) | |
| Improper Update of Reference Count | |
| Integer Overflow or Wraparound | |
| Incorrect Authorization | |
| Use of Externally-Controlled Format String | |
| Access Control Bypass | |
| Allocation of Resources Without Limits or Throttling | |
| Authorization Bypass Through User-Controlled Key | |
| Out-of-bounds Read | |
| Directory Traversal | |
| SQL Injection | |
| Server-side Request Forgery (SSRF) | |
| Buffer Overflow | |
| Cross-site Scripting (XSS) | |
| Incorrect Type Conversion or Cast | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | |
| Out-of-bounds Write | |
| Use of Hard-coded Credentials | |
| CVE-2018-4058 | |
| Incorrect Calculation | |
| NULL Pointer Dereference | |
| SQL Injection | |
| Improper Initialization | |