BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
eBay like Auction PHP Script 2.2 - 'id' Parameter SQL Injection13-09-2017
Hotel Reservation Site Script 3.3 - 'key' Parameter SQL Injection13-09-2017
Astaro Security Gateway 7 - Remote Code Execution13-09-2017
Gr8 Multiple Search Engine Script 1.0 - SQL Injection12-09-2017
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization12-09-2017
Jungo DriverWizard WinDriver <= 12.4.0 - Kernel Pool Overflow12-09-2017
FoodStar 1.0 - SQL Injection12-09-2017
inClick Cloud Server 5.0 - SQL Injection12-09-2017
osTicket 1.10 - SQL Injection12-09-2017
D-Link DIR8xx Routers - Local Firmware Upload12-09-2017
Consumer Review Script 1.0 - SQL Injection12-09-2017
D-Link DIR8xx Routers - Leak Credentials12-09-2017
D-Link DIR8xx Routers - Root Remote Code Execution12-09-2017
XYZ Auto Classifieds 1.0 - SQL Injection12-09-2017
Docker Daemon - Unprotected TCP Socket (Metasploit)11-09-2017
Hanbanggaoke IP Camera - Arbitrary Password Change11-09-2017
AirStar Airbnb Clone Script 1.0 - SQL Injection11-09-2017
iTech Book Store Script 2.02 - SQL Injection11-09-2017
EduStar Udemy Clone Script 1.0 - SQL Injection11-09-2017
iTech StockPhoto Script 2.02 - SQL Injection11-09-2017
Nimble Professional 1.0 - Cross-Site Request Forgery (Update Admin)11-09-2017
JobStar Monster Clone Script 1.0 - SQL Injection11-09-2017
PHP Dashboards NEW 4.4 - SQL Injection11-09-2017
PHP Dashboards NEW 4.4 - Arbitrary File Read11-09-2017
tcprewrite - Heap-Based Buffer Overflow11-09-2017
WiseGiga NAS - Multiple Vulnerabilities11-09-2017
Linux/ARM (Raspberry Pi) - Reverse TCP Shell (192.168.0.12:4444/TCP) Shellcode (160 bytes)10-09-2017
Linux/ARM (Raspberry Pi) - Bind TCP Shell (4444/TCP) Shellcode (192 bytes)10-09-2017
Law Firm 1.0 - SQL Injection09-09-2017
My Builder Marketplace 1.0 - SQL Injection09-09-2017