basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Zero Day Initiative
Research org contributor

Zero Day Initiative

cited as evidence in 8 · CNA assigner on 6 (independent) · credited finder on 45 of 57 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

zerodayinitiative.com ↗ · home of the cited advisories

Independent CNA
57
records cited in
deterministic count
45
finder / reporter credits
CVE.org credits
6
CVE records catalogued (CNA)
independent
60%
avg modeled exploit prob.
FIRST EPSS, 57/57
51%
ransomware-associated
29 of 57 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
43
Find
record(s)
0
Fix
record(s)
1
Exploit
record(s)
6
Catalog
record(s)

Part of the Trend Micro family — a hard rollup: this sub-unit’s work aggregates under Trend Micro.

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesOperating system / kernel (19), Application / other (17), Server / web platform (14), Hypervisor / virtualization (3), Browser (2)
WeaknessPath traversal / file (10), Injection (9), Memory safety (8), Authentication (8), Authorization / access control (4)
PortfolioMicrosoft (39), Progress (3), VMware (2), TP-Link (2), PaperCut (2), InduSoft (1)
PeopleNamed individuals credited under this contributor:
Anonymous working with Trend Micro's Zero Day Initiative · 5Orange Tsai(@orange_8361) from DEVCORE Research Team working · 3Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningT · 3ChenNan and RanchoIce of Tencent ZhanluLab working with Tren · 2DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q from GTSC working with Trend M · 2Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative · 2Jang (Nguyễn Tiến Giang) of StarLabs SG working with Trend M · 2Peter Girnus (gothburz) of Trend Micro's Zero Day Initiative · 2Zero Day Initiative (ZDI)Simon Zuckerbraun working with Trend Micro's Zero Day Initia
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
54reach this stage
2Keys to the kingdom
54reach this stage
3Lateral reach
51reach this stage
4Data at risk
10reach this stage
5Lights out
1reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 10 of 54 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 57, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2023-27350PaperCut100%RWKEVCVE-2021-34473Microsoft100%RWKEVCVE-2025-49704Microsoft100%RWKEVCVE-2021-34523Microsoft100%RWKEVCVE-2023-29357Microsoft100%RWKEVCVE-2022-41082Microsoft100%RWKEVCVE-2020-0688Microsoft100%RWKEVCVE-2022-41040Microsoft100%RWKEVCVE-2019-0604Microsoft100%RWKEVCVE-2021-31207Microsoft100%RWKEVCVE-2024-21412Microsoft95%RWKEVCVE-2024-6670Progress93%RWKEVCVE-2025-26399SolarWinds90%RWKEVCVE-2018-8174Microsoft88%RWKEVCVE-2023-24955Microsoft85%RWKEVCVE-2020-3992VMware83%RWKEVCVE-2019-0752Microsoft82%RWKEVCVE-2023-27351PaperCut78%RWKEVCVE-2024-30088Microsoft68%RWKEVCVE-2023-21529Microsoft62%RWKEVCVE-2026-59310Broadcom46%RWKEVCVE-2019-0841Microsoft41%RWKEVCVE-2018-8581Microsoft27%RWKEVCVE-2021-41379Microsoft20%RWKEVCVE-2019-1253Microsoft12%RWKEVCVE-2019-1388Microsoft9%RWKEVCVE-2019-1385Microsoft4%RWKEVCVE-2018-8405Microsoft3%RWKEVCVE-2018-8406Microsoft3%RWKEVCVE-2023-1389TP-Link100%KEVCVE-2024-4885Progress99%KEVCVE-2023-20887VMware98%KEVCVE-2021-33766Microsoft98%KEVCVE-2024-4358Progress97%KEVCVE-2024-7399Samsung92%KEVCVE-2025-6218RARLAB91%KEVCVE-2026-50522Microsoft85%KEVCVE-2022-26923Microsoft84%KEVCVE-2021-38406Delta Electronics76%KEVCVE-2014-0780InduSoft74%KEVCVE-2025-04117-Zip67%KEVCVE-2026-0770Langflow63%KEVCVE-2018-8373Microsoft62%KEVCVE-2024-43461Microsoft54%KEVCVE-2024-29988Microsoft45%KEVCVE-2024-35250Microsoft25%KEVCVE-2021-34484Microsoft22%KEVCVE-2019-1297Microsoft22%KEVCVE-2019-0903Microsoft22%KEVCVE-2020-0986Microsoft16%KEVCVE-2023-50224TP-Link16%KEVCVE-2024-38213Microsoft14%KEVCVE-2022-2586Linux10%KEVCVE-2024-38217Microsoft10%KEVCVE-2024-38014Microsoft6%KEVCVE-2024-30040Microsoft4%KEVCVE-2024-38226Microsoft3%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 57 known-exploited records — the list below; every one links to its public source.
  • Catalogued 6 CVE record(s) as the CNA assigner (from CVE.org).
  • Credited as the finder/reporter on 45 record(s) (CVE.org credits).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.