Good link for web security
1. SSRF
neerajedwards reading local file
2. Local file read
3. JWT
3. PHP
Remote code execution via PHP [Unserialize]
php object injection cheatsheet
expressionengine code reuse attack
File Operation Induced Unserialization via the “phar://” Stream Wrapper
4. Java
Serial Killer: Silently Pwning Your Java Endpoints
attacking-java-deserialization
5. XXE
6. XSS
Python template Injection
Summary of attacks against CTF Flask