Skip to content

OWASP Top 10

Definition

Open Worldwide Application Security Project's ranking of the most common web application security risks, refreshed every 3 to 4 years. Current edition: 2021, with A03 Injection, A07 Identification and Authentication Failures, and others.

Related terms

ARP Poisoning
Sending forged ARP replies on a LAN to bind an attacker's MAC to a victim's IP in other hosts' ARP caches, redirecting...
CVE / KEV
Common Vulnerabilities and Exposures (MITRE-assigned identifier per public flaw). Known Exploited Vulnerabilities catalogue (CISA), which lists CVEs proven to be actively exploited...
DDoS (Distributed Denial of Service)
Service-denial attack sourced from many hosts at once. Volumetric (saturate bandwidth), protocol (exhaust state on stateful boxes), or application-layer (exhaust application resources).
MITM (Man-in-the-Middle)
Any attack in which the adversary sits between two endpoints and reads or modifies traffic. ARP poisoning, rogue access points, BGP hijacks...
Packet Sniffing
Capture of network traffic from a wired tap, a switch SPAN port, or a Wi-Fi monitor-mode radio. Passive sniffing reads; active sniffing...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.