basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Trend Micro
Research org contributor

Trend Micro

cited as evidence in 61 · CNA assigner on 12 of 73 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

trendmicro.com ↗ · home of the cited advisories

73
records cited in
deterministic count
0
finder / reporter credits
CVE.org credits
12
CVE records catalogued (CNA)
assigner
61%
avg modeled exploit prob.
FIRST EPSS, 73/73
25%
ransomware-associated
18 of 73 · CISA flag
01

Known for

— recomputed from this contributor’s own records
SurfacesApplication / other (31), Operating system / kernel (13), Edge / remote-access infra (11), Browser (9), Server / web platform (7)
WeaknessMemory safety (20), Injection (17), Path traversal / file (6), Authorization / access control (5), Web / client (2)
PortfolioMicrosoft (15), Trend Micro (12), Google (8), Apache (4), Accellion (4), Adobe (3)
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
73reach this stage
2Keys to the kingdom
73reach this stage
3Lateral reach
68reach this stage
4Data at risk
6reach this stage
5Lights out
2reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 6 of 73 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 73, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2022-29464WSO2100%RWKEVCVE-2017-5638Apache100%RWKEVCVE-2021-42013Apache100%RWKEVCVE-2018-10562Dasan100%RWKEVCVE-2017-11882Microsoft100%RWKEVCVE-2017-12615Apache100%RWKEVCVE-2017-0144Microsoft99%RWKEVCVE-2024-21412Microsoft95%RWKEVCVE-2024-6670Progress95%RWKEVCVE-2018-8174Microsoft88%RWKEVCVE-2024-30088Microsoft68%RWKEVCVE-2023-28461Array Networks 68%RWKEVCVE-2021-27104Accellion57%RWKEVCVE-2018-13374Fortinet38%RWKEVCVE-2021-27103Accellion11%RWKEVCVE-2017-1000253Linux11%RWKEVCVE-2021-27101Accellion6%RWKEVCVE-2021-27102Accellion4%RWKEVCVE-2014-6271GNU100%KEVCVE-2021-40438Apache100%KEVCVE-2020-9054Zyxel100%KEVCVE-2015-1427Elastic100%KEVCVE-2017-7269Microsoft100%KEVCVE-2016-6277NETGEAR100%KEVCVE-2022-22965VMware100%KEVCVE-2015-5119Adobe99%KEVCVE-2014-6287Rejetto99%KEVCVE-2020-0618Microsoft99%KEVCVE-2008-4250Microsoft99%KEVCVE-2020-14883Oracle98%KEVCVE-2024-56145Craft CMS97%KEVCVE-2015-2051D-Link97%KEVCVE-2017-3506Oracle96%KEVCVE-2025-4008Smartbedded94%KEVCVE-2015-5122Adobe94%KEVCVE-2010-2568Microsoft91%KEVCVE-2017-5521NETGEAR89%KEVCVE-2023-36025Microsoft88%KEVCVE-2015-2426Microsoft87%KEVCVE-2018-17463Google84%KEVCVE-2014-4114Microsoft82%KEVCVE-2019-9621Synacor81%KEVCVE-2020-6418Google79%KEVCVE-2021-22555Linux79%KEVCVE-2023-4911GNU79%KEVCVE-2019-2215Android72%KEVCVE-2025-04117-Zip66%KEVCVE-2018-6065Google59%KEVCVE-2020-1054Microsoft53%KEVCVE-2016-1646Google45%KEVCVE-2015-2425Microsoft45%KEVCVE-2017-5030Google42%KEVCVE-2015-2387Microsoft37%KEVCVE-2016-5198Google35%KEVCVE-2018-17480Google34%KEVCVE-2017-5070Google31%KEVCVE-2019-18187Trend Micro25%KEVCVE-2025-54948Trend Micro20%KEVCVE-2022-26871Trend Micro20%KEVCVE-2015-5123Adobe18%KEVCVE-2022-22948VMware14%KEVCVE-2019-3010Oracle14%KEVCVE-2020-8599Trend Micro12%KEVCVE-2020-8467Trend Micro11%KEVCVE-2020-8468Trend Micro6%KEVCVE-2021-36741Trend Micro5%KEVCVE-2023-41179Trend Micro5%KEVCVE-2023-45727North Grid4%KEVCVE-2011-4723D-Link3%KEVCVE-2022-40139Trend Micro3%KEVCVE-2020-24557Trend Micro3%KEVCVE-2021-36742Trend Micro1%KEVCVE-2026-34926Trend Micro1%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 73 known-exploited records — the list below; every one links to its public source.
  • Catalogued 12 CVE record(s) as the CNA assigner (from CVE.org).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.