basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Trend Micro
Vendor security team contributor

Trend Micro

cited as evidence in 61 · CNA assigner on 12 · credited finder on 1 of 74 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

trendmicro.com ↗ · home of the cited advisories

74
records cited in
deterministic count
1
finder / reporter credits
CVE.org credits
12
CVE records catalogued (CNA)
assigner
60%
avg modeled exploit prob.
FIRST EPSS, 74/74
28%
ransomware-associated
21 of 74 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
1
Find
record(s)
12
Fix
record(s)
0
Exploit
record(s)
0
Catalog
record(s)

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesApplication / other (31), Operating system / kernel (13), Edge / remote-access infra (11), Browser (9), Server / web platform (7)
WeaknessMemory safety (20), Injection (17), Path traversal / file (6), Authorization / access control (5), Web / client (2)
PortfolioMicrosoft (15), Trend Micro (12), Google (8), Apache (4), Accellion (4), Adobe (3)
PeopleNamed individuals credited under this contributor:
Guy Lederfein of Trend Micro
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
74reach this stage
→
2Keys to the kingdom
74reach this stage
→
3Lateral reach
69reach this stage
→
4Data at risk
6reach this stage
→
5Lights out
2reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 6 of 74 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 74, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2022-29464WSO2100%RWKEVCVE-2021-40438Apache100%RWKEVCVE-2017-5638Apache100%RWKEVCVE-2021-42013Apache100%RWKEVCVE-2018-10562Dasan100%RWKEVCVE-2017-11882Microsoft100%RWKEVCVE-2017-12615Apache100%RWKEVCVE-2024-21412Microsoft99%RWKEVCVE-2017-0144Microsoft99%RWKEVCVE-2020-0618Microsoft99%RWKEVCVE-2024-6670Progress93%RWKEVCVE-2018-8174Microsoft88%RWKEVCVE-2024-30088Microsoft68%RWKEVCVE-2023-28461Array Networks 68%RWKEVCVE-2021-27104Accellion57%RWKEVCVE-2018-13374Fortinet38%RWKEVCVE-2024-37085VMware27%RWKEVCVE-2021-27103Accellion11%RWKEVCVE-2017-1000253Linux11%RWKEVCVE-2021-27101Accellion6%RWKEVCVE-2021-27102Accellion4%RWKEVCVE-2014-6271GNU100%KEVCVE-2020-9054Zyxel100%KEVCVE-2015-1427Elastic100%KEVCVE-2017-7269Microsoft100%KEVCVE-2016-6277NETGEAR100%KEVCVE-2022-22965VMware100%KEVCVE-2015-5119Adobe99%KEVCVE-2014-6287Rejetto99%KEVCVE-2008-4250Microsoft99%KEVCVE-2020-14883Oracle98%KEVCVE-2024-56145Craft CMS97%KEVCVE-2015-2051D-Link97%KEVCVE-2017-3506Oracle96%KEVCVE-2015-5122Adobe94%KEVCVE-2025-4008Smartbedded94%KEVCVE-2010-2568Microsoft91%KEVCVE-2017-5521NETGEAR89%KEVCVE-2023-36025Microsoft88%KEVCVE-2015-2426Microsoft87%KEVCVE-2018-17463Google85%KEVCVE-2014-4114Microsoft82%KEVCVE-2023-4911GNU81%KEVCVE-2019-9621Synacor81%KEVCVE-2020-6418Google79%KEVCVE-2021-22555Linux79%KEVCVE-2019-2215Android72%KEVCVE-2025-04117-Zip67%KEVCVE-2018-6065Google60%KEVCVE-2020-1054Microsoft54%KEVCVE-2016-1646Google48%KEVCVE-2015-2425Microsoft45%KEVCVE-2017-5030Google41%KEVCVE-2018-17480Google36%KEVCVE-2015-2387Microsoft35%KEVCVE-2016-5198Google34%KEVCVE-2017-5070Google32%KEVCVE-2019-18187Trend Micro25%KEVCVE-2025-54948Trend Micro22%KEVCVE-2022-26871Trend Micro19%KEVCVE-2015-5123Adobe19%KEVCVE-2019-3010Oracle13%KEVCVE-2022-22948VMware13%KEVCVE-2020-8599Trend Micro12%KEVCVE-2020-8467Trend Micro11%KEVCVE-2020-8468Trend Micro6%KEVCVE-2021-36741Trend Micro5%KEVCVE-2023-41179Trend Micro5%KEVCVE-2023-45727North Grid4%KEVCVE-2022-40139Trend Micro3%KEVCVE-2011-4723D-Link3%KEVCVE-2020-24557Trend Micro3%KEVCVE-2021-36742Trend Micro1%KEVCVE-2026-34926Trend Micro1%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 74 known-exploited records — the list below; every one links to its public source.
  • Catalogued 12 CVE record(s) as the CNA assigner (from CVE.org).
  • Credited as the finder/reporter on 1 record(s) (CVE.org credits).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.