What we look for
Auth bypass, broken access control, injection sinks (SQL, OS command, LDAP, NoSQL), deserialization, prototype pollution, SSRF, secret exposure, unsafe deserialization, and exploitable third-party calls. Per-language and per-framework.