BugSearch is an information portal focused on applications security, web oriented and not. We offer our services to disclose our registered users on security alerts found on the net, in order to warn them as soon as possible on bugs, system flaws, exploits and threats afflicting applications and possible patches.

New Feature: Post New Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Adult Script Pro 2.2.4 - SQL Injection30-10-2017
iProject Management System 1.0 - 'ID' SQL Injection30-10-2017
D-Park Pro 1.0 - SQL Injection30-10-2017
Online Exam Test Application - 'sort' SQL Injection30-10-2017
Php Inventory - Arbitrary File Upload30-10-2017
WordPress Plugin Ultimate Product Catalog 4.2.24 - PHP Object Injection30-10-2017
Vastal I-Tech Agent Zone - SQL Injection30-10-2017
Zomato Clone Script - 'resid' SQL Injection30-10-2017
Website Broker Script - 'status_id' SQL Injection30-10-2017
Oracle Java SE - Web Start jnlp XML External Entity Processing Information Disclosure30-10-2017
WordPress Plugin WPHRM - SQL Injection29-10-2017
Uniview - Remote Command Execution / Export Config (PoC)28-10-2017
PHP Melody 2.6.1 - SQL Injection28-10-2017
MitraStar DSL-100HN-T1/GPT-2541GNAC - Privilege Escalation28-10-2017
SmarterStats 11.3.6347 - Cross-Site Scripting27-10-2017
phpMyFAQ 2.9.8 - Cross-Site Request Forgery27-10-2017
Tizen Studio 1.3 Smart Development Bridge <2.3.2 - Buffer Overflow (PoC)27-10-2017
HitmanPro 3.7.15 Build 281 - Kernel Pool Overflow26-10-2017
Watchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference26-10-2017
Netgear DGN1000 1.1.00.48 - Setup.cgi Unauthenticated Remote Code Execution (Metasploit)25-10-2017
PHPMailer <= 5.2.21 - Local File Disclosure25-10-2017
KeystoneJS 4.0.0-beta.5 - Cross-Site Scripting25-10-2017
KeystoneJS 4.0.0-beta.5 - CSV Excel Macro Injection25-10-2017
FS Realtor Clone - 'id' SQL Injection24-10-2017
FS Crowdfunding Script - 'id' SQL Injection24-10-2017
FS Monster Clone - 'id' SQL Injection24-10-2017
FS Trademe Clone - 'id' SQL Injection24-10-2017
FS Care Clone - 'sitterService' SQL Injection24-10-2017
FS Thumbtack Clone - 'ser' SQL Injection24-10-2017
FS Shutter Stock Clone - 'keywords' SQL Injection24-10-2017