BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Microsoft Windows - Windows Error Reporting Local Privilege Escalation02-01-2019
WordPress Plugin Adicon Server 1.2 - 'selectedPlace' SQL Injection02-01-2019
Frog CMS 0.9.5 - Cross-Site Scripting02-01-2019
Vtiger CRM 7.1.0 - Remote Code Execution02-01-2019
NBMonitor Network Bandwidth Monitor 1.6.5.0 - 'Name' Denial of Service (PoC)02-01-2019
VMware Workstation/Player < 12.5.5 - Local Privilege Escalation30-12-2018
Deepin Linux 15 - 'lastore-daemon' Local Privilege Escalation30-12-2018
Linux Kernel 4.8.0-34 < 4.8.0-45 (Ubuntu / Linux Mint) - Packet Socket Local Privilege Escalation29-12-2018
Linux Kernel 4.4.0-21 < 4.4.0-51 (Ubuntu 14.04/16.04 x86-64) - 'AF_PACKET' Race Condition Privilege Escalation29-12-2018
Linux Kernel < 4.4.0/ < 4.8.0 (Ubuntu 14.04/16.04 / Linux Mint 17/18 / Zorin) - Local Privilege Escalation (KASLR / SMEP)29-12-2018
bludit Pages Editor 3.0.0 - Arbitrary File Upload27-12-2018
NetShareWatcher 1.5.8 - Denial of Service (PoC)27-12-2018
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File Upload27-12-2018
ShareAlarmPro 2.1.4 - Denial of Service (PoC)27-12-2018
Iperius Backup 5.8.1 - Buffer Overflow (SEH)27-12-2018
Terminal Services Manager 3.1 - Local Buffer Overflow (SEH)27-12-2018
Product Key Explorer 4.0.9 - Denial of Service (PoC)27-12-2018
WordPress Plugin Audio Record 1.0 - Arbitrary File Upload27-12-2018
MAGIX Music Editor 3.1 - Buffer Overflow (SEH)27-12-2018
Craft CMS 3.0.25 - Cross-Site Scripting27-12-2018
Linux/x86 - Kill All Processes Shellcode (14 bytes)24-12-2018
FrontAccounting 2.4.5 - 'SubmitUser' SQL Injection24-12-2018
Angry IP Scanner for Linux 3.5.3 - Denial of Service (PoC)24-12-2018
WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)24-12-2018
WSTMart 2.0.8 - Cross-Site Scripting24-12-2018
Adobe Flash ActiveX Plugin 28.0.0.137 - Remote Code Execution (PoC)24-12-2018
Netatalk < 3.1.12 - Authentication Bypass21-12-2018
SQLScan 1.0 - Denial of Service (PoC)21-12-2018
Microsoft Windows - 'MsiAdvertiseProduct' Arbitrary File Read21-12-2018
Microsoft Edge 42.17134.1.0 - 'Tree::ANode::DocumentLayout' Denial of Service21-12-2018