Stupid or small accidental or ???accidental??? mistakes in security code such as authentication and session management, access control, or in crypto or secrets handling Hard-coded URLs or IPs or other addresses, hard-coded user-ids and passwords or password hashes or keys in the code or in configuration.