I know SQL Injection is one... what are the others...
Sending plain text passwords without first encrypting them is never a good idea.