BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Wordpress Mini Mail Dashboard Widget Plugin 1.36 Remote File Inclusion 19-09-2011
Wordpress Zingiri Web Shop Plugin 2.2.0 Remote File Inclusion 19-09-2011
Wordpress Mailing List Plugin 1.3.2 Remote File Inclusion 19-09-2011
Wordpress Disclosure Policy Plugin 1.0 Remote File Inclusion 19-09-2011
Wordpress Livesig Plugin 0.4 Remote File Inclusion 19-09-2011
Wordpress Annonces Plugin 1.2.0.0 Remote File Inclusion 19-09-2011
Wordpress WPEasyStats Plugin 1.8 Remote File Inclusion 19-09-2011
Wordpress AllWebMenus Plugin 1.1.3 Remote File Inclusion 19-09-2011
Wordpress TheCartPress Plugin 1.1.1 Remote File Inclusion 19-09-2011
Toko Lite CMS 1.5.2 (edit.php) HTTP Response Splitting Vulnerability 19-09-2011
WordPress Filedownload Plugin 0.1 (download.php) Remote File Disclosure Vulnerability 19-09-2011
WordPress Count per Day plugin <= 2.17 SQL Injection Vulnerability 18-09-2011
KnFTP 1.0.0 Server Multiple Buffer Overflow Exploit (DoS PoC) 18-09-2011
MY MP3 Player 3.0 m3u Exploit DEP Bypass 17-09-2011
RealNetworks Realplayer QCP Parsing Heap Overflow - [CVE: 2011-2950] 17-09-2011
iManager Plugin v1.2.8 (lang) Local File Inclusion Vulnerability 17-09-2011
iBrowser Plugin v1.4.1 (lang) Local File Inclusion Vulnerability 17-09-2011
iManager Plugin v1.2.8 (d) Remote Arbitrary File Deletion Vulnerability 17-09-2011
Measuresoft ScadaPro <= 4.0.0 Remote Command Execution 16-09-2011
Mini-Stream Ripper 2.9.7 DEP Bypass 16-09-2011
outgoing.php Xss Vulnerability 15-09-2011
Nortel Contact Recording Centralized Archive 6.5.1 SQL Injection Exploit 15-09-2011
Measuresoft ScadaPro <= 4.0.0 Multiple Vulnerabilities 14-09-2011
Rockwell RSLogix <= 19 Denial of Service 14-09-2011
Progea Movicon / PowerHMI <= 11.2.1085 Multiple Vulnerabilities 14-09-2011
DAQFactory <= 5.85 build 1853 Stack Overflow 14-09-2011
Cogent DataHub <= 7.1.1.63 Source Disclosure 14-09-2011
Cogent DataHub <= 7.1.1.63 Integer Overflow 14-09-2011
Cogent DataHub <= 7.1.1.63 Stack Overflow 14-09-2011
eSignal and eSignal Pro <= 10.6.2425.1208 Multiple Vulnerabilites 14-09-2011