I know SQL Injection is one... what are the others...
OWASP.org keeps a list. Start with the OWASP top ten.