OWASP Top 10
Injection 注入攻击
Broken Authentication 失效的身份验证
Sensitive Data Exposure 敏感数据泄露
XML External Entity (XML外部实体漏洞
Broken Access Control无效的访冋控制
Security Misconfiguration安全配置错误
Cross-site Scripting (XSS)跨站脚本攻击
Insecure Deserialization不安全的反序列化漏洞
Using Known VulnerableComponents使用含有已知漏洞的组件
Insuficient Logging Monitoring日志与监控不足
OWASP Top 10