I just worked my way through the list SANS published. Looking at the list it is not surprising but scary to see which errors made it to the top of the list:
Cross-site Scripting
SQL Injection
Classic Buffer Overflow
Cross-Site Request Forgery
Improper Access Control
It ...
not tagged.