BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Foswiki MAKETEXT Remote Command Execution 23-12-2012
TWiki MAKETEXT Remote Command Execution 23-12-2012
Netwin SurgeFTP Remote Command Execution 23-12-2012
FireFly Mediaserver 1.0.0.1359 NULL Pointer Dereference 21-12-2012
Banana Dance B.2.6 Multiple Vulnerabilities 21-12-2012
Elite Bulletin Board 2.1.21 Multiple SQL Injection Vulnerabilities 21-12-2012
YeaLink IP Phone SIP-TxxP firmware <=9.70.0.100 Multiple Vulnerabilities 21-12-2012
Sony PC Companion 2.1 (Admin_RemoveDirectory()) Stack-based Unicode Buffer Overflow 21-12-2012
Sony PC Companion 2.1 (Load()) Stack-based Unicode Buffer Overflow 21-12-2012
Sony PC Companion 2.1 (DownloadURLToFile()) Stack-based Unicode Buffer Overflow 21-12-2012
Sony PC Companion 2.1 (CheckCompatibility()) Stack-based Unicode Buffer Overflow 21-12-2012
gdb (GNU debugger) <= 7.5.1NULL Pointer Dereference 20-12-2012
NetWin SurgeFTP Authenticated Admin Command Injection 20-12-2012
IDA Pro 6.3 Crash PoC 20-12-2012
InduSoft Web Studio ISSymbol.ocx InternationalSeparator() Heap Overflow 20-12-2012
SonicWall SonicOS 5.8.1.8 WAF XSS Vulnerability 19-12-2012
DIMIN Viewer 5.4.0 GIF Decode Crash PoC 19-12-2012
Free hosting manager v2.0.2 Stored XSS 19-12-2012
Enterpriser16 Load Balancer v7.1 Multiple XSS Vulnerabilities 19-12-2012
Clockstone and other CMSMasters Theme File Upload Vulnerabilities 19-12-2012
SMF All Version (Server Setting) Stored XSS Vulnerability18-12-2012
Crystal Reports CrystalPrintControl ActiveX ServerResourceVersion Property Overflow 18-12-2012
phpwcms <= v1.5.4.6 "preg_replace" Multiple Vulnerabilities 17-12-2012
MyBB All Version (Add Forum) Stored XSS17-12-2012
MyBB User Profile Skype ID Plugin 1.0 Stored XSS 16-12-2012
WebConnection Cross-Site Scripting Vulnerability16-12-2012
tristar Sql Injection Vulnerability16-12-2012
toto communications Cross-Site Scripting Vulnerability16-12-2012
Tides Center Cross-Site Scripting Vulnerability16-12-2012
studioumbrella Sql Injection Vulnerability16-12-2012