BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Solarwinds Orion Service - SQL Injection Vulnerabilities 04-03-2015
Symantec Web Gateway 5 restore.php Post Authentication Command Injection 04-03-2015
Linux Kernel IRET Instruction #SS Fault Handling - Crash PoC 04-03-2015
PHPMoAdmin Unauthorized Remote Code Execution (0-Day) 03-03-2015
vBulletin vBSEO 4.x.x 'visitormessage.php' Remote Code Injection Vulnerability 02-03-2015
Linux/ARM - Add Map (127.1.1.1 google.lk) In /etc/hosts Shellcode (79 bytes)02-03-2015
Persistent Systems Client Automation Command Injection RCE 27-02-2015
Ubisoft Uplay 5.0 - Insecure File Permissions Local Privilege Escalation 27-02-2015
Electronic Arts Origin Client 9.5.5 - Multiple Privilege Escalation Vulnerabilities 27-02-2015
HP Client Automation Command Injection 24-02-2015
N.E.T. E-Commerce Group Cross Site Scripting Vulnerability24-02-2015
phpBugTracker 1.6.0 - Multiple Vulnerabilities 23-02-2015
Zabbix 2.0.5 - Cleartext ldap_bind_password Password Disclosure (MSF) 23-02-2015
Zeuscart v.4 - Multiple Vulnerabilities 23-02-2015
WeBid 1.1.1 Unrestricted File Upload Exploit 23-02-2015
WordPress Easy Social Icons Plugin 1.2.2 - CSRF Vulnerability 23-02-2015
PHP DateTime Use After Free Vulnerability 23-02-2015
Samsung iPOLiS 1.12.2 - iPOLiS XnsSdkDeviceIpInstaller ActiveX WriteConfigValue PoC 23-02-2015
Clipbucket 2.7 RC3 0.9 - Blind SQL Injection 23-02-2015
Piwigo 2.7.3 - Multiple Vulnerabilities 19-02-2015
jQuery jui_filter_rules PHP Code Execution 19-02-2015
CrushFTP 7.2.0 - Multiple Vulnerabilities 19-02-2015
Piwigo 2.7.3 - SQL Injection 19-02-2015
Duplicator 0.5.8 Privilege Escalation 18-02-2015
X360 VideoPlayer ActiveX Control Buffer Overflow 17-02-2015
Java JMX Server Insecure Configuration Java Code Execution 17-02-2015
GuppY CMS 5.0.9 & 5.00.10 Multiple CSRF Vulnerabilities 17-02-2015
Guppy CMS 5.0.9 & 5.00.10 Authentication Bypass/Change Email 17-02-2015
eTouch SamePage 4.4.0.0.239 - Multiple Vulnerabilities 16-02-2015
Exponent CMS 2.3.1 - Multiple XSS Vulnerabilities 12-02-2015