How can we help you?
The public knowledge base by AssistSec. For every vulnerability: how it happens, how an attack unfolds and how you close it. Written by our pentesters, without the sales pitch.
81 vulnerabilities updated September 4, 2026
OWASP Top 10
81 vulnerabilities, filed against the standard's ten categories. Pick one to go straight to that part of the index.
Vulnerabilities
Everything in this reference, by name. For the full description of each vulnerability, go to the index.
- API responses contain too much data
- Application uses Basic Authentication
- Authentication cookie valid for too long
- Broken access control
- Broken authentication
- Brute force and credential stuffing
- Clickjacking
- CRLF injection and HTTP response splitting
- Cross-site request forgery (CSRF)
- Cross-site scripting (XSS)
- Cross-site scripting through file upload
- Cross-site WebSocket hijacking
- Cryptographic failures
- CSP allows inline scripts and eval
- CSV injection in export files
- Debug mode enabled in production
- Default web server files reachable
- Detailed error messages
- Directory structure visible
- Discovering valid usernames
- External scripts without integrity checking
- GraphQL introspection and unprotected fields
- Host header injection
- Information disclosure
- Input validation missing on the server
- Insecure CORS configuration
- Insecure deserialization
- Insecure direct object reference (IDOR)
- Insecure password storage
- Insecure transport and weak TLS
- Insufficient function level authorization
- Insufficient object level authorization in APIs
- Internal IP addresses and hostnames exposed
- IP address trusted from a header
- JWT stays valid after logout
- JWT vulnerabilities
- LDAP injection
- Mass assignment
- Metadata in published files
- MIME sniffing not disabled
- Missing Content Security Policy
- Missing HTTP Strict Transport Security
- Missing Permissions-Policy
- Missing Referrer-Policy
- Multi-factor authentication can be disabled without verification
- Multi-factor authentication is missing
- Multi-factor authentication is not enforced
- No rate limiting on the API
- No re-authentication for sensitive changes
- NoSQL injection
- Open redirect
- OS command injection
- Outdated and vulnerable components
- Outdated API versions remain reachable
- Password fields are autofilled
- Path traversal (directory traversal)
- Privilege escalation
- Prototype pollution
- Remote code execution (RCE)
- SameSite attribute set to Lax instead of Strict
- Security misconfiguration
- Sending email on behalf of your domain
- Sensitive data shared with analytics services
- Server-side request forgery (SSRF)
- Server-side template injection (SSTI)
- Session fixation
- Session identifier in the URL
- Session stays valid after an account is deleted
- Session stays valid after logout
- Sessions do not expire
- Source code publicly accessible
- SQL injection
- Unnecessary services reachable from the internet
- Unprotected authentication cookie
- Unrestricted file upload
- Unsafe HTTP methods permitted
- Uploading malicious files is possible
- Version information in HTTP headers
- Weak DKIM key
- Weak password requirements
- XML external entity injection (XXE)