Attacking a database through a vulnerable login system or search field.

Tricking a web application into exposing sensitive local files on the server. 2. Binary and System Exploits

Forcing a server to make requests to internal or external resources it shouldn't access.

Injecting malicious scripts into web pages viewed by other users.

These are often featured in technical "deep-dive" write-ups and CTF (Capture The Flag) walkthroughs.

These are the most common exploits documented by researchers in bug bounty programs like those on InfoSec Write-ups .