BugSearch è un portale d'informazione sul mondo della sicurezza web e non che offre una serie di servizi utili a divulgare rapidamente ai propri utenti registrati gli avvisi di sicurezza scoperti nella rete, in modo tale da poter essere avvisati tempestivamente su bachi, falle di sistema, exploit e threats che affliggono le applicazioni e correggerle nel minor tempo possibile.

Novità: Invia Nuovo Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Microsoft Windows - 'jscript!NameTbl::GetValDef' Use-After-Free19-12-2017
Joomla! Component My Projects 2.0 - SQL Injection18-12-2017
Zoom Linux Client 2.0.106600.0904 - Command Injection18-12-2017
Monstra CMS 3.0.4 - Arbitrary File Upload / Remote Code Execution18-12-2017
Joomla! Component User Bench 1.0 - 'userid' SQL Injection18-12-2017
Joomla! Component Guru Pro - 'promocode' SQL Injection18-12-2017
Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow18-12-2017
Outlook for Android - Attachment Download Directory Traversal18-12-2017
Western Digital MyCloud - 'multi_uploadify' File Upload (Metasploit)18-12-2017
CDex 1.96 - Buffer Overflow18-12-2017
Joomla! Component JB Visa 1.0 - 'visatype' SQL Injection18-12-2017
GoAhead httpd 2.5 < 3.6.5 - 'LD_PRELOAD' Remote Code Execution18-12-2017
Linux/x64 - Custom Encoded XOR + execve(/bin/sh) Shellcode16-12-2017
Movie Guide 2.0 - SQL Injection15-12-2017
Sync Breeze 10.2.12 - Denial of Service15-12-2017
Linux kernel < 4.10.15 - Race Condition Privilege Escalation15-12-2017
ITGuard-Manager 0.0.0.1 - Remote Code Execution15-12-2017
Bus Booking Script 1.0 - 'txtname' SQL Injection14-12-2017
pfSense 2.4.1 - Cross-Site Request Forgery Error Page Clickjacking (Metasploit)14-12-2017
Microsoft Office - Dynamic Data Exchange 'DDE' Payload Delivery (Metasploit)14-12-2017
Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit)14-12-2017
Dup Scout Enterprise - 'Login' Buffer Overflow (Metasploit)14-12-2017
Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection14-12-2017
Palo Alto Networks Firewalls - Root Remote Code Execution14-12-2017
Multiple OEM - 'nsd' Remote Stack Format String (PoC)14-12-2017
CMS DESIGNED BY WDD xxS14-12-2017
Linksys WVBR0 - 'User-Agent' Remote Command Injection14-12-2017
Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read13-12-2017
vBulletin 5 - 'routestring' Unauthenticated Remote Code Execution13-12-2017
vBulletin 5 - 'cacheTemplates' Unauthenticated Remote Arbitrary File Deletion13-12-2017