| Use of Web Link to Untrusted Target with window.opener Access | medium |
| Use of Hard-coded Credentials | low |
| Use of Hard-coded Credentials | low |
| Use of Hard-coded Credentials | low |
| Use of Hard-coded Credentials | medium |
| Use of Hard-coded Credentials | medium |
| Use of Hard-coded Credentials | medium |
| Unintended Proxy or Intermediary ('Confused Deputy') | medium |
| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | low |
| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | low |
| Origin Validation Error | medium |
| Missing Support for Integrity Check | low |
| Insertion of Sensitive Information into Log File | low |
| Insertion of Sensitive Information into Externally-Accessible File or Directory | high |
| Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | low |
| Inadequate Encryption Strength | medium |
| Inadequate Encryption Strength | high |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | high |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | high |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | high |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | low |
| Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') | low |
| Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') | medium |
| Improper Management of Sensitive Trace Data | low |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | low |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | medium |
| Improper Export of Android Application Components | medium |
| Improper Encoding or Escaping of Output | low |
| Improper Control of Generation of Code ('Code Injection') | high |
| Exposure of Sensitive Information to an Unauthorized Actor | high |
| Exposure of Sensitive Information to an Unauthorized Actor | high |
| Cross-Site Request Forgery (CSRF) | low |
| Cross-Site Request Forgery (CSRF) | high |
| Cross-Site Request Forgery (CSRF) | medium |
| Cross-Site Request Forgery (CSRF) | low |
| Creating Debug Binary | low |
| Configuration | low |
| Configuration | low |
| Configuration | low |
| Cleartext Transmission of Sensitive Information | low |
| Authentication Bypass by Spoofing | low |
| Active Debug Code | low |