Watch it done
Short walkthroughs — the technique, start to finish. Pair one with the concept and the labs in the same category.
AllAuthentication bypassBroken access control / IDORSQL / command injectionBusiness logic flawPrivilege escalationCryptographic weaknessCSRFInsecure deserializationInformation disclosureRemote code executionRace conditionAccess control & business logicWeb applicationServer-side request forgery (SSRF)Subdomain takeoverCross-site scripting (XSS)