Server-Side
- SQL Injection
- SSRF
- XXE Injection
- Path Traversal
- File Upload Vulnerabilities
- NoSQL Injection
- Authentication
- OS Command Injection
- Business Logic Vulnerabilities
- Information Disclosure
- Broken Access Control
- Race Conditions
Client-Side
- Cross-Site Scripting
- Cross-Site Request Forgery
- Cross-Origin Resource Sharing
- WebSocket
- DOM Clobbering