Remote Code Execution (RCE) - SQL Injection - Authentication/Authorization bypass - Cross-Site Scripting (XSS) -- usually stored/reflected, sometimes DOM-based - Server-Side Request Forgery (SSRF) - Insecure Direct Object Reference (IDOR) - Information disclosure (sensitive data exposure)