BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
IlohaMail Webmail Stored XSS 18-08-2012
Apple Quicktime plugin - Windows 4.1.2 (Japanese) Remote Overflow Vulnerability 18-08-2012
Jaow CMS v2.3 Blind SQLi Vulnerability 17-08-2012
WeBid <= 1.0.4 Multiple Vulnerabilities 17-08-2012
T-dah Webmail Multiple Stored XSS 17-08-2012
Hastymail2 Webmail 1.1 RC2 Stored XSS 17-08-2012
Elastix 2.2.0 LFI Exploit 17-08-2012
Inferno vBShout <= 2.5.2 SQL Injection 17-08-2012
ManageEngine OpStor v7.4 Multiple Vulnerabilities 17-08-2012
Social Engine v4.2.5 Multiple Vulnerabilities 17-08-2012
Winamp Browser Memory Corruption Vulnerability13-08-2012
FreeBSD Kernel SCTP Remote NULL Ptr Dereference DoS 03-08-2012
Zenoss 3 showDaemonXMLConfig Command Execution 03-08-2012
Dell SonicWALL Scrutinizer 9 SQL Injection 03-08-2012
Cisco Linksys PlayerPT ActiveX Control SetSource sURL argument Buffer Overflow 03-08-2012
Nvidia Linux Driver Privilege Escalation 02-08-2012
Joomla joomgalaxy 1.2.0.4 Multiple Vulnerabilities 02-08-2012
Linux x86 chmod 666 /etc/passwd & /etc/shadow - 57 bytes 02-08-2012
Microsoft Internet Explorer Fixed Table Col Span Heap Overflow 02-08-2012
WebPageTest Arbitrary PHP File Upload 02-08-2012
Linux x86 ASLR deactivation - 83 bytes 02-08-2012
ManageEngine Mobile Application Manager v10 SQL Injection 01-08-2012
ManageEngine Application Manager 10 Multiple Vulnerabilities 01-08-2012
Joomla Movm Extension (com_movm) SQL Injection 01-08-2012
pBot Remote Code Execution 01-08-2012
eGlibc Signedness Code Execution Vulnerability 01-08-2012
Joomla com_niceajaxpoll <= 1.3.0 SQL Injection Vulnerability 01-08-2012
Dr. Web Control Center 6.00.3.201111300 XSS Vulnerability 31-07-2012
Symantec Web Gateway 5.0.3.18 (deptUploads_data.php groupid parameter) Blind SQLi 30-07-2012
Sysax Multi-Server 5.64 Create Folder Buffer Overflow 29-07-2012