Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.| cwe.mitre.org
The Ten Most Critical API Security Risks| owasp.org