A document listing the top 10 web application security vulnerabilities updated every 3 to 4 years. Required reading before the CISSP exam. Free at owasp.org.
Want to actually apply concepts like this instead of just reading definitions?
Practice free on Zamlom