BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Joomla! Component SIMGenealogy 2.1.5 - SQL Injection02-08-2017
Entrepreneur B2B Script - 'pid' Parameter SQL Injection02-08-2017
Joomla! Component PHP-Bridge 1.2.3 - SQL Injection02-08-2017
Joomla! Component Event Registration Pro Calendar 4.1.3 - SQL Injection02-08-2017
Joomla! Component Ultimate Property Listing 1.0.2 - SQL Injection02-08-2017
Joomla! Component LMS King Professional 3.2.4.0 - SQL Injection02-08-2017
Premium Servers List Tracker 1.0 - SQL Injection02-08-2017
Muviko 1.0 - 'q' Parameter SQL Injection02-08-2017
EDUMOD Pro 1.3 - SQL Injection02-08-2017
iOS/macOS - xpc_data Objects Sandbox Escape Privelege Escalation01-08-2017
SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection01-08-2017
libmad 0.15.1b - 'mp3' Memory Corruption01-08-2017
VehicleWorkshop - Authentication Bypass01-08-2017
VehicleWorkshop - Arbitrary File Upload01-08-2017
Advantech SUSIAccess <= 3.0 - 'RecoveryMgmt' File Upload01-08-2017
Advantech SUSIAccess <= 3.0 - Directory Traversal / Information Disclosure (Metasploit)01-08-2017
Solarwinds Kiwi Syslog 9.6.1.6 - Denial of Service01-08-2017
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities31-07-2017
libvorbis 1.3.5 - Multiple Vulnerabilities31-07-2017
Vorbis Tools oggenc 1.4.0 - '.wav' Denial of Service31-07-2017
libao 1.2.0 - Denial of Service31-07-2017
DivFix++ 0.34 - Denial of Service31-07-2017
McAfee Security Scan Plus - Remote Command Execution30-07-2017
DiskBoss Enterprise 8.2.14 - Buffer Overflow30-07-2017
Jenkins < 1.650 - Java Deserialization30-07-2017
libjpeg-turbo 1.5.1 - Denial of Service28-07-2017
LAME 3.99.5 - Multiple Vulnerabilities28-07-2017
SoundTouch 1.9.2 - Multiple Vulnerabilities28-07-2017
VehicleWorkshop - SQL Injection28-07-2017
FortiOS < 5.6.0 - Cross-Site Scripting28-07-2017