The
OWASP Top 10 is the most referenced web application security risk list. 2021 edition top risks: Broken Access Control, Cryptographic Failures, Injection, Insecure Design, Security Misconfiguration.
OWASP Top 10 is not a checklist — it's a risk awareness document. Every developer should know it. "Broken Access Control" moved to #1 in 2021 (was #5). Used as a security requirement baseline globally.