BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
X2Engine 4.2 - CSRF Vulnerability 25-09-2015
FortiManager 5.2.2 - Persistent XSS Vulnerabilities 25-09-2015
WinRar 5.21 - SFX OLE Command Execution 25-09-2015
FreshFTP 5.52 - .qfl Crash PoC 25-09-2015
X2Engine 4.2 - Arbitrary File Upload 25-09-2015
SMF (Simple Machine Forum) <= 2.0.10 - Remote Memory Exfiltration Exploit 24-09-2015
Windows Kernel - NtGdiBitBlt Buffer Overflow (MS15-097) 24-09-2015
w3tw0rk / Pitbul IRC Bot Remote Code Execution 23-09-2015
Cisco AnyConnect 3.1.08009 - Privilege Escalation via DMG Install Script 23-09-2015
refbase <= 0.9.6 - Multiple Vulnerabilities 23-09-2015
Windows Kernel - NtGdiStretchBlt Pool Buffer Overflows (MS15-097) 22-09-2015
Kaspersky Antivirus VB6 Parsing Integer Overflow 22-09-2015
Kaspersky Antivirus ExeCryptor Parsing Memory Corruption 22-09-2015
Kaspersky Antivirus PE Unpacking Integer Overflow 22-09-2015
Kaspersky Antivirus ThinApp Parser Stack Buffer Overflow 22-09-2015
Kaspersky Antivirus "Yoda's Protector" Unpacking Memory Corruption 22-09-2015
Cisco AnyConnect Secure Mobility Client 3.1.08009 - Privilege Escalation 22-09-2015
Kaspersky Antivirus UPX Parsing Memory Corruption 22-09-2015
Kaspersky Antivirus CHM Parsing Stack Buffer Overflow 22-09-2015
Kaspersky Antivirus DEX File Format Parsing Memory Corruption 22-09-2015
OS X Regex Engine (TRE) - Stack Buffer Overflow 22-09-2015
OS X Regex Engine (TRE) - Integer Signedness and Overflow Issues 22-09-2015
SAP Netweaver < 7.01 - XML External Entity Injection 22-09-2015
Kirby CMS <= 2.1.0 - Authentication Bypass 22-09-2015
Air Drive Plus 2.4 - Arbitrary File Upload Vulnerability 22-09-2015
MASM32 11R - Crash POC 22-09-2015
Konica Minolta FTP Utility 1.0 - Directory Traversal Vulnerability 22-09-2015
h5ai < 0.25.0 - Unrestricted File Upload 22-09-2015
Konica Minolta FTP Utility 1.0 - Remote Command Execution 21-09-2015
Konica Minolta FTP Utility 1.00 Post Auth CWD Command SEH Overflow 21-09-2015