BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Just Dial Marketplace 1.0 - SQL Injection09-09-2017
Topsites Script 1.0 - Cross-Site Request Forgery / PHP Code Injection09-09-2017
Law Firm 1.0 - SQL Injection09-09-2017
Babysitter Website Script 1.0 - SQL Injection09-09-2017
Online Print Business 1.0 - SQL Injection09-09-2017
Job Board Software 1.0 - SQL Injection09-09-2017
Professional Service Booking 1.0 - SQL Injection09-09-2017
Restaurant Website Script 1.0 - SQL Injection09-09-2017
HiSilicon DVR Devices - Remote Code Execution07-09-2017
Huawei HG255s - Directory Traversal07-09-2017
Roteador Wireless Intelbras WRN150 - Cross-Site Scripting07-09-2017
Gh0st Client - Buffer Overflow (Metasploit)07-09-2017
McAfee LiveSafe 16.0.3 - Man In The Middle Registry Modification Leading to Remote Command Execution07-09-2017
Online Invoice System 3.0 - SQL Injection07-09-2017
EzBan 5.3 - 'id' Parameter SQL Injection07-09-2017
EzInvoice 6.02 - SQL Injection07-09-2017
Tor - Linux Sandbox Breakout via X1106-09-2017
Jungo DriverWizard WinDriver - Kernel Pool Overflow06-09-2017
Jungo DriverWizard WinDriver - Kernel Out-of-Bounds Write Privilege Escalation06-09-2017
Pay Banner Text Link Ad 1.0.6.1 - SQL Injection06-09-2017
Advertiz PHP Script 0.2 - Cross-Site Request Forgery (Update Admin)06-09-2017
Pay Banner Text Link Ad 1.0.6.1 - Cross-Site Request Forgery (Update Admin)06-09-2017
Cory Support - 'pr' Parameter SQL Injection06-09-2017
Apache Struts 2.5 - Remote Code Execution06-09-2017
The Car Project 1.0 - SQL Injection05-09-2017
Ultimate HR System <= 1.2 - Directory Traversal / Cross-Site Scripting05-09-2017
FiberHome ADSL AN1020-25 - Improper Access Restrictions05-09-2017
Dup Scout Enterprise 9.9.14 - 'Input Directory' Local Buffer Overflow04-09-2017
CodeMeter 6.50 - Cross-Site Scripting04-09-2017
RubyGems < 2.6.13 - Arbitrary File Overwrite04-09-2017