OWASP Top 10
InformationalOWASP Top 10
Definition
The OWASP Top 10 is a reference document published by the Open Web Application Security Project that lists the 10 most critical security-risk categories in web applications. It is updated periodically and is the de facto standard for web security assessment. The 2021 version includes: Broken Access Control, Cryptographic Failures, Injection, Insecure Design, Security Misconfiguration, and more.
Impact
Examples
OWASP Top 10 - 2021
The 10 categories are: A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection, A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable and Outdated Components, A07 Identification and Authentication Failures, A08 Software and Data Integrity Failures, A09 Security Logging and Monitoring Failures, A10 Server-Side Request Forgery (SSRF).