OWASP API Top 10
A separate API list exists because API risks genuinely differ in kind from web application risks.
The dominant problems are authorisation at the object level, excessive data exposure and unrestricted resource consumption, none of which are the classic injection flaws. Applying web application thinking to APIs consistently misses the categories that actually cause API breaches.
Checked against the primary source.
