BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Logpoint < 5.6.4 - Unauthenticated Root Remote Code Execution11-06-2017
WordPress Plugin WP Jobs < 1.5 - SQL Injection11-06-2017
PaulShop - SQL Injection10-06-2017
Disk Sorter 9.7.14 - 'Input Directory' Local Buffer Overflow10-06-2017
eCom Cart 1.3 - SQL Injection10-06-2017
VMware vSphere Data Protection 5.x/6.x - Java Deserialization10-06-2017
libcroco 0.6.12 - Denial of Service09-06-2017
libquicktime 1.2.4 - Denial of Service09-06-2017
Apple macOS 10.12.3 / iOS < 10.3.2 - Userspace Entitlement Checking Race Condition09-06-2017
Apple macOS - Disk Arbitration Daemon Race Condition09-06-2017
Mapscrn 2.03 - Local Buffer Overflow09-06-2017
EFS Easy Chat Server 3.1 - Buffer Overflow (SEH)09-06-2017
EFS Easy Chat Server 3.1 - Password Disclosure09-06-2017
EFS Easy Chat Server 3.1 - Password Reset09-06-2017
IPFire 2.19 - Remote Code Execution09-06-2017
nuevoMailer 6.0 - SQL Injection09-06-2017
CMS Web Design Manchester SQL Injection |[+]08-06-2017
Windows - UAC Protection Bypass via FodHelper Registry Key (Metasploit)08-06-2017
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities08-06-2017
VMware Workstation 12 Pro - Denial of Service08-06-2017
Net Monitor for Employees Pro <= 5.3.4 - Unquoted Service Path Privilege Escalation08-06-2017
Craft CMS 2.6 - Cross-Site Scripting08-06-2017
Bl4ck M4n07-06-2017
DC/OS Marathon UI - Docker Exploit (Metasploit)07-06-2017
Linux Kernel - 'ping' Local Denial of Service07-06-2017
PuTTY < 0.68 - 'ssh_agent_channel_data' Integer Overflow Heap Corruption07-06-2017
Linux Kernel < 4.10.13 - 'keyctl_set_reqkey_keyring' Local Denial of Service07-06-2017
Robert 0.5 - Multiple Vulnerabilities07-06-2017
Xavier 2.4 - SQL Injection07-06-2017
Grav CMS 1.4.2 Admin Plugin - Cross-Site Scripting07-06-2017