BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Absolute File Send 1.0 Remote Cookie Handling Vulnerability30-10-2008
Opera 9.62 (opera:allinone) Remote Code Execution Exploit PoC30-10-2008
Absolute Poll Manager XE 4.1 Cookie Handling Vulnerability30-10-2008
DjVu ActiveX Control 3.0 ImageURL Property Overflow Exploit30-10-2008
Visagesoft eXPert PDF ViewerX (VSPDFViewerX.ocx) File Overwrite29-10-2008
Harlandscripts Pro Traffic One (mypage.php) SQL Injection Vulnerability29-10-2008
MW6 Aztec ActiveX (Aztec.dll) Remote Insecure Method Exploit29-10-2008
MW6 DataMatrix ActiveX (DataMatrix.dll) Insecure Method Exploit29-10-2008
MW6 Barcode ActiveX (Barcode.dll) Insecure Method Exploit29-10-2008
MW6 PDF417 ActiveX (MW6PDF417.dll) Remote Insecure Method Exploit29-10-2008
7Shop <= 1.1 Remote Arbitrary File Upload Exploit29-10-2008
Mambo Component SimpleBoard <= 1.0.1 Arbitrary File Upload Exploit29-10-2008
Wordpress Plugin e-Commerce <= 3.4 Arbitrary File Upload Exploit29-10-2008
WebCards <= 1.3 Remote SQL Injection Vulnerability29-10-2008
Sepal SPBOARD 4.5 (board.cgi) Remote Command Exec Vulnerability29-10-2008
e107 Plugin fm pro v1 (FD-Upload-DT) Multiple Remote Vulnerabilities29-10-2008
H2O-CMS <= 3.4 Insecure Cookie Handling Vulnerability29-10-2008
PacketTrap TFTPD 2.2.5459.0 Remote Denial of Service Exploit29-10-2008
Pro Traffic One (poll_results.php id) Remote SQL Injection Vulnerability29-10-2008
Venalsur on-line Booking Centre (OfertaID) XSS-SQL Injection Vulns29-10-2008
H2O-CMS <= 3.4 Remote Command Execution Exploit (mq = off)28-10-2008
Agares ThemeSiteScript 1.0 (loadadminpage) RFI Vulnerability28-10-2008
TlGuestBook 1.2 Insecure Cookie Handling Vulnerability28-10-2008
e107 Plugin BLOG Engine 2.1.4 Remote SQL Injection Vulnerability28-10-2008
PersianBB (iranian_music.php id) Remote SQL Injection Vulnerability28-10-2008
MyForum 1.3 Insecure Cookie Handling Vulnerability28-10-2008
e107 Plugin alternate_profiles (id) SQL Injection Vulnerability27-10-2008
TlAds v1 Remote Insecure Cookie Handling Vulnerability27-10-2008
MyKtools 2.4 (langage) Local File Inclusion Vulnerability27-10-2008
MyForum 1.3 (padmin) Local File Inclusion Vulnerability27-10-2008