Internal network scanning via JavaScript - Port scanning behind the firewall - DNS rebinding attacks - Cross-origin data theft (via CORS misconfig)