A01:2021 — Broken Access Control
94% tested
A02:2021 — Cryptographic Failures
was Sensitive Data Exposure
A03:2021 — Injection (incl. XSS)
33 CWEs
A04:2021 — Insecure Design
new in 2021
A05:2021 — Security Misconfiguration
was #6
A06:2021 — Vulnerable & Outdated Components
moved up from #9
A07:2021 — Identification & Authentication Failures
was Broken Auth
A08:2021 — Software & Data Integrity Failures
new in 2021
A09:2021 — Security Logging & Monitoring Failures
survey #3
A10:2021 — Server-Side Request Forgery (SSRF)
community #1 pick