BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
RSVP Invitation Online 1.0 - Cross-Site Request Forgery (Update Admin)23-01-2018
LiveCRM SaaS Cloud 1.0 - SQL Injection23-01-2018
Tumder 2.1 - SQL Injection23-01-2018
Easy Car Script 2014 - SQL Injection23-01-2018
Blizzard Update Agent - JSON RPC DNS Rebinding23-01-2018
Linux/x86 - execve(/bin/sh) + ROT-N + Shift-N + XOR-N Encoded Shellcode (77 bytes)23-01-2018
NEC Univerge SV9100/SV8100 WebPro 10.0 - Configuration Download23-01-2018
HP Connected Backup 8.6/8.8.6 - Local Privilege Escalation23-01-2018
CentOS Web Panel 0.9.8.12 - 'row_id' / 'domain' SQL Injection23-01-2018
MixPad 5.00 - Buffer Overflow23-01-2018
RAVPower 2.000.056 - Memory Disclosure23-01-2018
Flexible Poll 1.2 - SQL Injection23-01-2018
Quickad 4.0 - SQL Injection23-01-2018
Herospeed - 'TelnetSwitch' Remote Stack Overflow / Overwrite Password / Enable TelnetD22-01-2018
AsusWRT Router < 3.0.0.4.380.7743 - Unauthenticated LAN Remote Code Execution22-01-2018
CentOS Web Panel 0.9.8.12 - Multiple Vulnerabilities21-01-2018
OTRS 5.0.x/6.0.x - Remote Command Execution21-01-2018
PHPFreeChat 1.7 - Denial of Service21-01-2018
Oracle JDeveloper 11.1.x/12.x - Directory Traversal21-01-2018
Shopware 5.2.5/5.3 - Cross-Site Scripting21-01-2018
macOS 10.13 (17A365) - Kernel Memory Disclosure due to Lack of Bounds Checking in 'AppleIntelCapriController::getDisplayPipeCapability'19-01-2018
Smiths Medical Medfusion 4000 - 'DHCP' Denial of Service18-01-2018
GitStack 2.3.10 - Unauthenticated Remote Code Execution18-01-2018
Primefaces 5.x - Remote Code Execution (Metasploit)18-01-2018
Microsoft Edge Chakra JIT - Incorrect Bounds Calculation17-01-2018
Microsoft Edge Chakra JIT - Out-of-Bounds Write17-01-2018
Microsoft Edge Chakra JIT - Stack-to-Heap Copy17-01-2018
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes (2)17-01-2018
Microsoft Edge Chakra - Incorrect Scope Handling17-01-2018
Microsoft Edge Chakra - 'AsmJSByteCodeGenerator::EmitCall' Out-of-Bounds Read17-01-2018