- Misc
- OAuth
- Open Redirect
- Command Injection
- Local File Inclusion (LFI)
- Insecure File Upload
- Insecure Direct Object Reference (IDOR)
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Server Side Request Forgery (SSRF)
- Server Side Template Injection (SSTI)
- XML External Entity (XXE)