BugSearch è un portale d'informazione sul mondo della sicurezza web e non che offre una serie di servizi utili a divulgare rapidamente ai propri utenti registrati gli avvisi di sicurezza scoperti nella rete, in modo tale da poter essere avvisati tempestivamente su bachi, falle di sistema, exploit e threats che affliggono le applicazioni e correggerle nel minor tempo possibile.

Novità: Invia Nuovo Exploit

Register now to start receiving our security alerts of your favourite applications or try our new Android App which will keep you updated everywhere you are!


Last Advisories
Serviio PRO 1.8 DLNA Media Streaming Server - REST API Arbitrary Code Execution03-05-2017
Ghostscript 9.21 - Type Confusion Arbitrary Command Execution (Metasploit)02-05-2017
Dahua Generation 2/3 - Backdoor Access02-05-2017
Joomla com_tag Component - 'Tag' Parameter Sql Injection Vulnerability02-05-2017
Alerton Webtalk 2.5 / 3.3 - Multiple Vulnerabilities01-05-2017
MySQL < 5.6.35 / < 5.7.17 - Integer Overflow01-05-2017
Tuleap Project Wiki 8.3 < 9.6.99.86 - Command Injection01-05-2017
HideMyAss Pro VPN Client for macOS 3.x - Privilege Escalation01-05-2017
HideMyAss Pro VPN Client for OS X 2.2.7.0 - Privilege Escalation01-05-2017
Emby MediaServer 3.2.5 - Directory Traversal30-04-2017
Emby MediaServer 3.2.5 - SQL Injection30-04-2017
Emby MediaServer 3.2.5 - Password Reset30-04-2017
Panda Free Antivirus - 'PSKMAD.sys' Denial of Service29-04-2017
IrfanView 4.44 - Denial of Service29-04-2017
Admidio 3.2.8 - Cross-Site Request Forgery28-04-2017
Mercurial - Custom hg-ssh Wrapper Remote Code Exec (Metasploit)27-04-2017
Easy File Uploader - Arbitrary File Upload27-04-2017
Simple File Uploader - Arbitrary File Download27-04-2017
Microsoft Internet Explorer 11.576.14393.0 - 'CStyleSheetArray::BuildListOfMatchedRules' Memory Corruption27-04-2017
TYPO3 News Module - SQL Injection27-04-2017
Revive Ad Server 4.0.1 - Cross-Site Scripting / Cross-Site Request Forgery26-04-2017
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion25-04-2017
Microsoft Windows 2003 SP2 - 'ERRATICGOPHER' SMB Remote Code Execution25-04-2017
Oracle VirtualBox Guest Additions 5.1.18 - Unprivileged Windows User-Mode Guest Code Double-Free25-04-2017
WePresent WiPG-1000 - Command Injection (Metasploit)25-04-2017
OpenText Documentum Content Server - dm_bp_transition.ebs docbase Method Arbitrary Code Execution25-04-2017
Microsoft Office Word - '.RTF' Malicious HTA Execution (Metasploit)25-04-2017
Apple Safari - Array concat Memory Corruption25-04-2017
WordPress Plugin Wow Viral Signups 2.1 - SQL Injection 25-04-2017
WordPress Plugin Car Rental System 2.5 - SQL Injection 25-04-2017