I'll keep it short and to the point. I'm currently taking a ciber-security course where we cover OWASP's top 10s (API and Web Apps), but I just can't seem to get the difference between those 2 concepts/terms. I mean, I just get EXTREMELY confused when they say: "ok, so Injection is 1st place in top 10 for Web Applications, but 8th in API"
The main problem with all of this is that not even OWASP's official site provides a clarification of the differences between "Web Apps" and "APIs" (or why there are 2 "top 10s"), and I haven't been able to find the answer elsewhere (to the point I ended up reaching the 4th page on google results).
Is the "Web Apps top 10" only referring to the front-end?
Is the "APIs top 10" referring to both: web APIs and non-web-based APIs?
If anyone could provide me with a good clarification of the differences between those 2 concepts, I'd really appreciate it.