The Open Web Application Security Project (OWASP) is a non-profit organization founded in 2001, with the goal of helping website owners and security experts protect web applications from cyber attacks.
Injection. Broken Authentication. Sensitive Data Exposure. XML External Entities (XEE). Broken Access Control. ... Security Misconfiguration. Cross-Site Scripting. Insecure Deserialization.
A vulnerability is a hole or a weakness in the application, which can be a design flaw or an implementation bug, that allows an attacker to cause harm to the stakeholders of an application. Stakeholders include the application owner, application users, and other entities that rely on the application.