The most widely-known list of critical web application security risks, updated periodically by OWASP.
The 2021 list runs from A01 Broken Access Control to A10 Server-Side Request Forgery. The OWASP API Security Top 10 is a separate but complementary list focused on API-specific risks. See our explainer for engineer-friendly walkthroughs.
See our web application penetration testing, API security testing, network penetration testing, and cloud security audit services for how we test for and defend against this class of issue.
30-minute call with an OSCP-certified engineer. Tailored proposal in 24 hours.