1 Injection (SQL, LDAP, &c)
2 AuthN (login, sessions)
3 XSS
4 AuthZ ("forced browsing", direct object references)
5 Insecure defaults
6 Lack of encryption (CC#'s, passwords)
7 Clientside access control only
8 CSRF
9 Known vulnerabilities (nginx, openssl, &c)
10 Insecure redirects
A better list for 2014:
1. AuthZ
2. XSS and backend/DOM sanitization
3. CSRF
4. Insecure cryptography (password resets, session cookies, SSO)
5. SQLI / database injection
6. Mass assignment
7. Application/API security mismatch
8. Insecure password storage
9. SSL/TLS hygiene (secure flag, HSTS, &c)
10. Insecure redirects
If you're looking for great security findings, I think it's more productive to list the 10 most dangerous features rather than 10 specific bug classes, because security flaws have a long tail, and the "thickness" of the tail doesn't correlate with severity. A good list of 10 deadly features:
1. Password reset
2. Administrative features (in-band and as sidecar applications)
3. User-exposed templates (incl. things like Markdown)
4. File upload/download
5. "Advanced search"
6. "Thick client" analogues (Websockets, plugins, Chrome extensions, &c)
7. Single sign-on (also things like OAuth)
8. Email gateways
9. Account data import/export
10. Gateways to other APIs (roughly, anything that requires your application to itself make HTTP requests to other applications)
This isn't an argument against these features; just, this is where most Matasano people would look first if they were in a race to find the first gameover of a pentest.