Information leak/disclosure
Auth issues
Reflective XSS
Open Redirect
Stored XSS
Deserialization
Application/Business Logic