All categories

API Attacks

#web#api#bola
Open

Broken Authentication & JWT

#web#jwt#authentication
Open

Business Logic Vulnerabilities

#web#business-logic#logic-flaw
Open

Clickjacking (UI Redressing)

#web#clickjacking#ui-redressing
Open

Command Injection

#web#command-injection#rce
Open

CORS Misconfiguration

#web#cors#same-origin-policy
Open

CRLF Injection / HTTP Response Splitting

#web#crlf-injection#header-injection
Open

Cross-Site Request Forgery (CSRF)

#web#csrf#session
Open

Cross-Site Scripting (XSS)

#web#xss#session-hijacking
Open

CSS Injection

#web#css-injection#data-exfiltration
Open

DNS Rebinding

#web#dns-rebinding#ssrf
Open

DOM-Based Vulnerabilities

#web#dom#dom-xss
Open

Encoding & Obfuscation

#web#encoding#obfuscation
Open

Eval Injection / Code Injection

#web#eval-injection#code-injection
Open

File Inclusion (LFI / RFI)

#web#lfi#rfi
Open

File Upload Attacks

#web#file-upload#webshell
Open

GraphQL

#web#graphql#introspection
Open

gRPC & Protobuf Security Testing

#web#grpc#protobuf
Open

Hash Length Extension Attack

#web#hash-extension#cryptography
Open

HTML Injection

#web#html-injection#phishing
Open

HTTP & Web Requests

#web#http#curl
Open

HTTP Host Header Attacks

#web#host-header#password-reset-poisoning
Open

HTTP Parameter Pollution (HPP)

#web#hpp#parameter-pollution
Open

HTTP Request Smuggling

#web#http-smuggling#request-smuggling
Open

Information Disclosure

#web#information-disclosure#recon
Open

Insecure Deserialization

#web#deserialization#ysoserial
Open

LaTeX Injection

#web#latex-injection#rce
Open

LDAP Injection

#web#ldap-injection#active-directory
Open

NoSQL Injection

#web#nosql-injection#mongodb
Open

OAuth 2.0 & OpenID Connect Attacks

#web#oauth#openid-connect
Open

Open Redirect

#web#open-redirect#oauth
Open

OWASP Top 10

#web#owasp#methodology
Open

Padding Oracle Attack

#web#padding-oracle#cryptography
Open

Parameter Logic Bugs

#web#logic-bugs#parameter-manipulation
Open

PDF Generation Vulnerabilities

#web#pdf#ssrf
Open

PHP Type Juggling

#web#php#type-juggling
Open

Prototype Pollution

#web#prototype-pollution#javascript
Open

Race Conditions

#web#race-conditions#toctou
Open

ReDoS (Regular Expression Denial of Service)

#web#redos#dos
Open

SAML Attacks

#web#saml#sso
Open

Second-Order Injection

#web#second-order#sql-injection
Open

Server-Side Parameter Pollution (SSPP)

#web#sspp#parameter-injection
Open

Session Fixation

#web#session-fixation#session-hijacking
Open

Session Puzzling (Session Variable Overloading)

#web#session-puzzling#auth-bypass
Open

SMTP Header Injection

#web#smtp-injection#email
Open

SOAP & WSDL Attacks

#web#soap#wsdl
Open

SQL Injection

#web#sql-injection#union
Open

SQLMap Essentials

#web#sqlmap#sql-injection
Open

SSI & XSLT Injection

#web#ssi#xslt
Open

SSRF

#web#ssrf#cloud-metadata
Open

SSTI

#web#ssti#rce
Open

Subdomain Takeover

#web#subdomain-takeover#dns
Open

Tabnabbing & Reverse Tabnabbing

#web#tabnabbing#reverse-tabnabbing
Open

Timing Attacks

#web#timing-attacks#user-enumeration
Open

TLS / HTTPS Attacks

#web#tls#ssl
Open

Weak Session IDs

#web#session-ids#brute-force
Open

Web Attacks (IDOR / Verb Tampering / BFLA)

#web#idor#bfla
Open

Web Cache Deception

#web#cache-deception#cache
Open

Web Cache Poisoning

#web#cache-poisoning#portswigger
Open

Web LLM Attacks & Prompt Injection

#web#llm#prompt-injection
Open

Web Recon & Fuzzing

#web#ffuf#fuzzing
Open

WebSockets Security

#web#websockets#cswsh
Open

XPath Injection

#web#xpath-injection#xml
Open

XXE

#web#xxe#xml
Open