BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Vtiger CRM 5.0.4 (RCE-CSRF-LFI-XSS) Multiple Vulnerabilities18-08-2009
BaBB 2.8 Remote Code Injection Exploit18-08-2009
HTML Email Creator & Sender 2.3 Local Buffer Overflow PoC (SEH)18-08-2009
Linux Kernel < 2.6.30.5 cfg80211 Remote Denial of Service Exploit18-08-2009
Adobe JRun 4 (logfile) Directory Traversal Vulnerability (auth)18-08-2009
PHP-Lance 1.52 Multiple Local File Inclusion Vulnerabilities18-08-2009
Linux Kernel 2.x sock_sendpage() Local Root Exploit (Android Edition)18-08-2009
Ignition 1.2 (comment) Remote Code Injection Vulnerability14-08-2009
PHP Competition System <= 0.84 (competition) SQL Injection Vuln14-08-2009
VLC Media Player <= 1.0.1 smb:-- URI Handling Remote BOF Exploit14-08-2009
Linux Kernel 2.x sock_sendpage() Local Root Exploit #214-08-2009
Linux Kernel 2.x sock_sendpage() Local Ring0 Root Exploit14-08-2009
Linux Kernel < 2.6.31-rc3 PER_CLEAR_ON_SETID Local Root Exploit14-08-2009
DS CMS 1.0 (nFileId) Remote SQL Injection Vulnerability14-08-2009
MyWeight 1.0 Remote Shell Upload Vulnerability14-08-2009
TGS CMS 0.x (XSS-SQL-FD) Multiple Remote Vulnerabilities13-08-2009
Wordpress Plugin WP-Syntax <= 0.9.1 Remote Command Execution PoC13-08-2009
THOMSON ST585 (user.ini) Arbitrary Download Vulnerability13-08-2009
Gazelle CMS 1.0 Remote Arbitrary Shell Upload Vulnerability13-08-2009
EmbedThis Appweb v3.0B.2-4 Multiple Remote Buffer Overflow PoC13-08-2009
JBLOG 1.5.1 Remote SQL Table Backup Exploit13-08-2009
VLC Media Player 1.0.0-1.0.1 smb:-- URI Handling BOF PoC13-08-2009
pIPL 2.5.0 (.PLS -.PL) Universal Local Buffer Exploit (SEH)13-08-2009
FTPShell Client 4.1 RC2 Name Session Stack Overflow Exploit13-08-2009
MS Wordpad on winXP SP3 Local Crash Exploit12-08-2009
Plume CMS 1.2.3 Multiple SQL Injection Vulnerabilities12-08-2009
Gazelle CMS 1.0 Multiple Vulnerabilities - RCE Exploit12-08-2009
2WIRE Gateway Authentication Bypass & Password Reset Vulnerabilities12-08-2009
Gallarific 1.1 (gallery.php) Arbitrary Delete-Edit Category Vuln12-08-2009
Shorty 0.7.1b (Auth Bypass) Insecure Cookie Handling Vulnerability12-08-2009