Server Side
SQL injection
Authentication
Path traversal
Command injection
Business logic vulnerabilities
Information disclosure
File upload vulnerabilities
Server-side request forgery (SSRF)
XXE injection
NoSQL injection
API testing
Client Side
Cross-site scripting (XSS)
Cross-site request forgery (CSRF)
Clickjacking
DOM-based vulnerabilities
WebSockets
Cross-origin resource sharing (CORS)
Advanced Topics
Insecure deserialization
GraphQL API vulnerabilities
Server-side template injection
Web cache poisoning
HTTP Host header attacks
HTTP request smuggling
OAuth authentication
JWT attacks
Prototype pollution