StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 2: Threats, vulnerabilities & mitigations

OWASP Top 10: broken access control, injection, misconfiguration, integrity failures, SSRF

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

The Open Worldwide Application Security Project (OWASP) is a nonprofit community that publishes free guidance on web application security. Its best-known document, the OWASP Top 10, ranks the most critical categories of web application security risk based on real-world data. It is updated every few years, so the exact order and names change, but the core categories are durable and Security+ expects you to recognize them and their defenses. Developers use the list to prioritize secure coding, and security teams use it to scope testing and code review.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan