C3:2018- Secure Database Access API5:2023 - Broken Function Level Authorization A10:2013- Unvalidated Redirects and Forwards API10:2023 - Unsafe Consumption of APIs API2:2023 - Broken Authentication API6:2023 - Unrestricted Access to Sensitive Business Flows A3:2017- Sensitive Data Exposure API4:2023 - Unrestricted Resource Consumption A9:2017- Using Components with Known Vulnerabilities A7:2013- Missing Function Level Access Control A5:2017- Broken Access Control A2:2017- Broken Authentication A4:2013- Insecure Direct Object References API9:2023 - Improper Inventory Management A1:2013- Injection A1:2017- Injection A6:2013- Sensitive Data Exposure A5:2013- Security Misconfiguration A8:2013- Cross-Site Request Forgery (CSRF) API3:2023 - Broken Object Property Level Authorization C1:2018- Define Security Requirements API1:2023 - Broken Object Level Authorization A10:2017- Insufficient Logging & Monitoring C4:2018- Encode and Escape Data A9:2013- Using Components with Known Vulnerabilities A7:2017- Cross-Site Scripting (XSS) API6:2023 - Unrestricted Access to Sensitive Business Flows A3:2013- Cross-Site Scripting (XSS) A8:2017- Insecure Deserialization C2:2018- Leverage Security Frameworks and Libraries API8:2023 - Security Misconfiguration A4:2017- XML External Entities (XXE) A6:2017- Security Misconfiguration A2:2013- Broken Authentication and Session Management C3:2018- Secure Database Access API5:2023 - Broken Function Level Authorization A10:2013- Unvalidated Redirects and Forwards API10:2023 - Unsafe Consumption of APIs API2:2023 - Broken Authentication API6:2023 - Unrestricted Access to Sensitive Business Flows A3:2017- Sensitive Data Exposure API4:2023 - Unrestricted Resource Consumption A9:2017- Using Components with Known Vulnerabilities A7:2013- Missing Function Level Access Control A5:2017- Broken Access Control A2:2017- Broken Authentication A4:2013- Insecure Direct Object References API9:2023 - Improper Inventory Management A1:2013- Injection A1:2017- Injection A6:2013- Sensitive Data Exposure A5:2013- Security Misconfiguration A8:2013- Cross-Site Request Forgery (CSRF) API3:2023 - Broken Object Property Level Authorization C1:2018- Define Security Requirements API1:2023 - Broken Object Level Authorization A10:2017- Insufficient Logging & Monitoring C4:2018- Encode and Escape Data A9:2013- Using Components with Known Vulnerabilities A7:2017- Cross-Site Scripting (XSS) API6:2023 - Unrestricted Access to Sensitive Business Flows A3:2013- Cross-Site Scripting (XSS) A8:2017- Insecure Deserialization C2:2018- Leverage Security Frameworks and Libraries API8:2023 - Security Misconfiguration A4:2017- XML External Entities (XXE) A6:2017- Security Misconfiguration A2:2013- Broken Authentication and Session Management
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
C3:2018-Secure Database Access
API5:2023 - Broken Function Level Authorization
A10:2013-Unvalidated Redirects and Forwards
API10:2023 - Unsafe Consumption of APIs
API2:2023 - Broken Authentication
API6:2023 - Unrestricted Access to Sensitive Business Flows
A3:2017-Sensitive Data Exposure
API4:2023 - Unrestricted Resource Consumption
A9:2017-Using Components with Known Vulnerabilities
A7:2013-Missing Function Level Access Control
A5:2017-Broken Access Control
A2:2017-Broken Authentication
A4:2013-Insecure Direct Object References
API9:2023 - Improper Inventory Management
A1:2013-Injection
A1:2017-Injection
A6:2013-Sensitive Data Exposure
A5:2013-Security Misconfiguration
A8:2013-Cross-Site Request Forgery (CSRF)
API3:2023 - Broken Object Property Level Authorization
C1:2018-Define Security Requirements
API1:2023 - Broken Object Level Authorization
A10:2017-Insufficient Logging & Monitoring
C4:2018-Encode and Escape Data
A9:2013-Using Components with Known Vulnerabilities
A7:2017-Cross-Site Scripting (XSS)
API6:2023 - Unrestricted Access to Sensitive Business Flows
A3:2013-Cross-Site Scripting (XSS)
A8:2017-Insecure Deserialization
C2:2018-Leverage Security Frameworks and Libraries
API8:2023 - Security Misconfiguration
A4:2017-XML External Entities (XXE)
A6:2017-Security Misconfiguration
A2:2013-Broken Authentication and Session Management