Start here
Reviewed 2026-09-13
Vulnerability index¶
Start with the operation you need to protect. Each reviewed guide includes context, a bounded remediation example and a regression check. A CWE identifies a weakness class; the presence of a page does not establish a scanner detection guarantee.
Choose a programming language · Investigate a finding · Understand coverage
Injection¶
- SQL Injection: Parameterized Queries and Safe Examples
- NoSQL Injection: Typed Queries and Operator Controls
- OS Command Injection: Safe Process Invocation
- Cross-Site Scripting (XSS): Context-Aware Prevention
- Autoescaping and context-aware HTML output
- XML External Entity (XXE): Secure Parser Configuration
- Server-Side Template Injection: Keep Templates Trusted
- Prototype Pollution in JavaScript and TypeScript
- LDAP Injection: Escape Filter Values and Bind Parameters
- XPath Injection: Bind Values or Compare Parsed XML Data
- Eval Code Injection: Keep Untrusted Values Out of Source
- Dynamic code execution from untrusted input
- Regular Expression Injection: Literal Search and Regex Limits
- HTML injection and safe text output
Web and API¶
- Broken Object-Level Authorization and IDOR
- Server-Side Request Forgery (SSRF): Restrict Outbound Requests
- CSRF Prevention: Protect Cookie-Authenticated Actions
- CORS Configuration: Trusted Origins and Credentials
- HTTP Method Security: Safe Semantics and Authorization
- Open Redirect: Fixed Destinations and Safe Return Paths
- Mass Assignment and Overposting
- Insecure File Upload — Validation and Private Storage
- Unsafe Archive Extraction and Zip Slip
- Path Traversal: Safe File Access and Containment
- Insecure Deserialization: Safe Data Parsing Patterns
- Information Disclosure Through Errors and Debug Output
- Information leakage through errors and responses
- Sensitive Logging and Log Injection
- Uncontrolled Resource Consumption and Denial of Service
Authentication and cryptography¶
- JWT Validation: Signature, Algorithm and Claims
- Session fixation and session ID renewal
- Password Policy: Length, Blocklists and MFA
- Weak Hashing: Digests, HMAC and Password Storage
- Hardcoded Passwords, API Keys and Secrets
- Hardcoded API keys and cryptographic secrets
- Password Lockout Disabled
- Insecure Cookie Flag
- Weak SSL and TLS protocol configuration
- SSL and TLS Verification Settings in Go, Ruby and PHP
- Disabled TLS Certificate Validation
- Cleartext Protocols: Require Verified TLS for Sensitive Data
- SMTP TLS configuration and credential protection
- Database access and authentication misconfiguration
- Cipher Modes: Authenticated Encryption and Nonce Safety
- Cryptographic Key Length: Algorithm-Specific Choices
- Weak Symmetric Algorithm
- Insecure Randomness: Generate Unpredictable Security Tokens
Native code and delivery¶
- C and C++ Memory Safety — Bounds and Lifetimes
- Integer Overflow and Allocation Size Checks
- Format String Injection in C, C++ and Objective-C
- Mobile Application Security for Android and iOS
- Infrastructure as Code Security — Terraform and Kubernetes
- Dependency and Software Supply Chain Security
- Prompt Injection and Safe AI Tool Boundaries
Framework and code-quality references¶
The Framework and code quality navigation covers .NET, browser APIs, resource management and reliability. Legacy framework guides explain the relevant version and migration boundary. A reliability or maintainability finding is not automatically a security vulnerability.