BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Allomani Mobile 2.5 Remote Blind SQL Injection Exploit27-07-2009
Allomani Songs & Clips 2.7.0 Blind SQL Injection Exploit27-07-2009
Allomani Movies & Clips 2.7.0 Remote Blind SQL Injection Exploit27-07-2009
VS PANEL 7.5.5 (Cat_ID) SQL Injection Vulnerability (patched?)27-07-2009
Cisco WLC 4402 Basic Auth Remote Denial of Service (meta)27-07-2009
PHP Paid 4 Mail Script (home.php page) Remote File Inclusion Vuln27-07-2009
Super Mod System v3 (s) SQL Injection Vulnerability27-07-2009
XOOPS Celepar Module Qas (bSQL-XSS) Multiple Remote Vulnerabilities27-07-2009
GarageSalesJunkie (SQL-XSS) Multiple Remote Vulnerabilities27-07-2009
URA 3.0 (cat) remote SQL injection Vulnerability27-07-2009
stftp <= 1.10 (PWD Response) Remote Stack Overflow PoC27-07-2009
ISC DHCP dhclient < 3.1.2p1 Remote Buffer Overflow PoC27-07-2009
iWiccle 1.01 (LFI-SQL) Multiple Remote Vulnerabilities27-07-2009
Joomla Almond Classifieds 7.5 (com_aclassf) Multiple Vulnerabilities27-07-2009
Almond Classifieds Ads (bSQL-XSS) Multiple Remote Vulnerabilities27-07-2009
SkaDate Dating (RFI-LFI-XSS) Multiple Remote Vulnerabilities27-07-2009
PHP Live! <= 3.2.2 (questid) Remote SQL Injection Vulnerability24-07-2009
Clip Bucket <= 1.7.1 Insecure Cookie Handling Vulnerability24-07-2009
Scripteen Free Image Hosting Script 2.3 Insecure Cookie Handling Vuln24-07-2009
Pixaria Gallery 2.3.5 (file) Remote File Disclosure Exploit24-07-2009
Scripteen Free Image Hosting Script 2.3 SQL Injection Exploit24-07-2009
MS Internet Explorer 7-8 findText Unicode Parsing Crash Exploit24-07-2009
SaphpLesson v4.0 (Auth Bypass) SQL Injection Vulnerability24-07-2009
Xoops Celepar Module Qas (codigo) SQL Injection Vulnerability24-07-2009
Wordpress 2.8.1 (url) Remote Cross Site Scripting Exploit24-07-2009
Deonixscripts Templates Management 1.3 SQL Injection Vulnerability24-07-2009
PHP Live! 3.2.1-2 (x) Remote Blind SQL Injection Exploit24-07-2009
Basilic 1.5.13 (index.php idAuthor) SQL Injection Vulnerability24-07-2009
Mozilla Firefox 3.5 (Font tags) Remote Buffer Overflow Exploit (osx)24-07-2009
OpenH323 Opal SIP Protocol Remote Denial of Service Exploit24-07-2009