Reflective XSS
Auth issues
Application/Business Logic
Stored XSS
Deserialization
Information leak/disclosure
RCE
SQL Injection