I know SQL Injection is one... what are the others...
In addition to the wonderful guidance on OWASP, also check out the SANS/CWE.