Server-Side Request Forgery (SSRF)
here
Cross-Site Request Forgery (CSRF)
here
Cross-Site Scripting (XSS)
here
XML External Entity (XXE)
here
Stored Procedure & Prepared Statement
here
OAuth works and Attack
here
SAML working and attacks
here
Scenario Based Question
here
WebView
here
SSTI & CSTI Injection
here
Challenging-AppSec-Question
here