BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Jiofi 4 (JMR 1140 Amtel_JMR1140_R12.07) - Cross-Site Request Forgery (Password Disclosure)13-02-2019
Jiofi 4 (JMR 1140 Amtel_JMR1140_R12.07) - Reflected Cross-Site Scripting13-02-2019
runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (2)13-02-2019
NetworkSleuth 3.0 - 'Name' Denial of Service (PoC)13-02-2019
Rukovoditel Project Management CRM 2.4.1 - Cross-Site Scripting13-02-2019
Jiofi 4 (JMR 1140 Amtel_JMR1140_R12.07) - Cross-Site Request Forgery (Admin Token Disclosure)13-02-2019
PilusCart 1.4.1 - 'send' SQL Injection13-02-2019
Jenkins 2.150.2 - Remote Command Execution (Metasploit)12-02-2019
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution12-02-2019
OPNsense < 19.1.1 - Cross-Site Scripting12-02-2019
LayerBB 1.1.2 - Cross-Site Scripting12-02-2019
runc< 1.0-rc6 (Docker < 18.09.2) - Host Command Execution12-02-2019
Android - binder Use-After-Free of VMA via race Between reclaim and munmap12-02-2019
Ubuntu snapd < 2.37.1 - Local Privilege Escalation12-02-2019
Skyworth GPON HomeGateways and Optical Network Terminals - Stack Overflow12-02-2019
Android - binder Use-After-Free via fdget() Optimization12-02-2019
Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)11-02-2019
IP-Tools 2.5 - Local Buffer Overflow (SEH) (Egghunter)11-02-2019
FutureDj Pro 1.7.2.0 - Denial of Service11-02-2019
Coship Wireless Router 4.0.0.x/5.0.0.x - WiFi Password Reset11-02-2019
River Past Cam Do 3.7.6 - Local Buffer Overflow (SEH)11-02-2019
AirDroid 4.2.1.6 - Denial of Service11-02-2019
Smoothwall Express 3.1-SP4 - Cross-Site Scripting11-02-2019
Indusoft Web Studio 8.1 SP2 - Remote Code Execution11-02-2019
MyBB Bans List 1.0 - Cross-Site Scripting11-02-2019
Webiness Inventory 2.3 - 'email' SQL Injection11-02-2019
VA MAX 8.3.4 - Authenticated Remote Code Execution11-02-2019
NUUO NVRmini - upgrade_handle.php Remote Command Execution (Metasploit)11-02-2019
NordVPN 6.19.6 - Denial of Service (PoC)11-02-2019
IPFire 2.21 - Cross-Site Scripting11-02-2019