Vulnerability scanning is a security review step that uses a known list of typical security vulnerabilities to manually check the code.
Static Analysis can partially automate this step but some vulnerabilities are not automatically discoverable.
These are some lists of vulnerabilities to look for: