Most of us in the software development eco-system are familiar with OWASP and the OWASP Top Ten project that enumerates top 10 security risks focusing on "traditional" web (server) applications. Thanks to the eco-system, there are 18 other such projects at various maturity levels focusing on many other facets of Software eco-system.
The Original OWASP Top Ten: https://owasp.org/www-project-top-ten/
Other OWASP Top Ten projects
Check them out and if you are new to any of these, please consider using them as your starting points, only as starting points, to learn, research, train and implement protections as part of overall security strategy.