No single tool covers the whole list.
Ten vulnerability categories, each caught by a different combination of tools — exactly why a mature pipeline layers SAST, SCA, and DAST together.
A01
Broken access control
A02
Crypto failures
A03
Injection
A04
Insecure design
A05
Security misconfig
A06
Vulnerable components
A07
Auth failures
A08
Data integrity failures
A09
Logging failures
A10
SSRF
Cheapest checks first, most expensive last
1
SASTevery commit
→
2
SCAevery dep change
→
3
DASTneeds staging, runs last
Fail fast on cheap checks before paying for expensive ones — SAST/SCA on every commit, DAST only once something is actually running.