Your Progress
9 of 42 lessons completed
Broken Access Control
Moving up from fifth position, 94% of applications were tested for some form of broken access control.
Cryptographic Failures
Previously known as Sensitive Data Exposure, focuses on failures related to cryptography.
Injection
94% of applications tested for injection, including SQL, NoSQL, OS, and LDAP injection.
Insecure Design
A new category focusing on risks related to design and architectural flaws.
Security Misconfiguration
90% of applications were tested for some form of misconfiguration.
Vulnerable Components
Using components with known vulnerabilities is a common and dangerous practice.
Auth Failures
Confirmation of identity, authentication, and session management vulnerabilities.
Data Integrity Failures
New category focusing on software and data integrity failures.
Logging Failures
Without proper logging and monitoring, breaches cannot be detected.
SSRF
Server-Side Request Forgery flaws occur when fetching remote resources.