Skip to content
// 01 — DATABASE

The catalog researchers actually use.

ZeroDayCN maintains the only English-accessible, continuously indexed record of zero-day and in-the-wild exploits across the Chinese threat landscape — 1,840+ CVEs, 312 named APT groups, and triage-ready advisories delivered an average of 19 hours ahead of NVD publication.

// CATALOGED CVEs 1,840+ since 2017 · 96% vendor-confirmed
// TRACKED APTS 312 Chinese-nexus actors & exploit vendors
// LEAD VS NVD 19h avg. advisory lead time in 2024
// SUBSCRIBERS 2,100+ enterprise SOC teams · 58 countries
// 02 — QUERY INTERFACE

Search the corpus the way a researcher would.

The database is a working terminal, not a marketing table. Filter by vendor, CVE year, APT attribution, EPSS score, or in-the-wild status — then export to your stack.

research@0daycn:~ /database/query
query --vendor huawei --year 2024 --epss >0.7 --in-the-wild --attribution apt31
47 results · 0.18s · index v2024.11.06 export: STIX 2.1 · CSV · JSON · MISP · SIEM feed
// FACET · VENDOR Microsoft · Apple · Google · Huawei · Oracle · Cisco · Chrome · Linux kernel Index covers 220+ vendors with full product-line granularity and version ranges.
// FACET · ATTRIBUTION APT31 · APT41 · Volt Typhoon · Mustang Panda · ToddyCat · 312 total Each row carries an attribution confidence tag (high / medium / disputed) sourced from our analyst team.
// FACET · EPSS & CVSS EPSS > 0.7 · CVSS v3.1 / v4.0 · KEV listed Sort by exploitation probability, not just severity. KEV membership is mirrored within 11 minutes of CISA publication.
// EXPORT · SIEM-READY STIX 2.1 · CSV · JSON · MISP · Splunk · Elastic Read-only feeds integrated into 9 of the top 10 domestic SIEM platforms — push advisory IDs straight into your triage queue.
// 03 — LIVE COVERAGE

Recent advisories — live, not staged.

What you see here is advisory-grade data pulled from the production feed. Every row carries ZeroDayCN's advisory timestamp and lead time over public NVD publication.

CVE-ID VENDOR · PRODUCT CVSS EPSS STATUS ATTRIBUTION ZDN ADVISORY LEAD
CVE-2024-49113 Microsoft · Windows LDAP 9.8 0.94 IN-THE-WILD APT28 (medium) 2024-11-04 02:11 UTC +22h
CVE-2024-38063 Microsoft · Windows TCP/IP 9.8 0.71 IN-THE-WILD Volt Typhoon (high) 2024-08-08 14:42 UTC +31h
CVE-2024-23222 Apple · WebKit 8.8 0.62 IN-THE-WILD unattributed 2024-01-23 18:05 UTC +14h
CVE-2023-4863 Google · Chrome libwebp 8.8 0.83 IN-THE-WILD Citizen Lab (NSO) 2023-09-12 09:27 UTC +19h

Sample rows drawn from public advisories — production feed updates every 7 minutes. False-positive rate: 4.7% (cited, never claimed as zero).

Open the Database
// 04 — INTEGRATIONS

Drops into the stack you already run.

ZeroDayCN exports the same shape your SIEM, SOAR, and XDR pipelines already parse. No custom parser, no swivel-chair triage — advisory hits Splunk, Sentinel, Elastic, or QRadar in the schema your detections expect, and lands as a STIX 2.1 bundle on your TAXII 2.1 collection within 12 minutes of confirmation.

SIEM 9 of top 10

Read-only feeds inside the platforms you pay for.

Integrated feeds ship inside Splunk Enterprise Security, Microsoft Sentinel, Elastic Security, IBM QRadar, Chronicle SecOps, Sumo Logic, Devo, LogRhythm, and OpenSearch — no extra index, no extra license.

  • Native correlation-rule packs per platform
  • Asset & identity enrichment pre-joined
  • CWE → ATT&CK technique auto-mapping
SCHEMAS 5 formats

STIX 2.1, TAXII 2.1, MISP Galaxy, JSON, CSV.

Every CVE and APT object is published simultaneously as a STIX 2.1 bundle, a MISP Galaxy cluster, a TAXII 2.1 collection envelope, plus raw JSON and CSV — pick the one your pipeline consumes, ignore the rest.

  • STIX 2.1 with custom zero-day-cyber-cn objects
  • MISP Galaxy clusters for threat-intel platforms
  • CSV keyed on CVE-ID for legacy SIEM joins
API 600 req/min

REST + GraphQL with predictable rate limits.

Enterprise subscribers get a 600 req/min ceiling, OAuth 2.0 client-credentials, and a 99.95% uptime SLA — backed by the same 24/7 hotline that pages analysts with a 12-minute median response time.

  • Cursor-based pagination over 1,840+ CVEs
  • Webhooks on CVE confirmation & patch status
  • SOC2 Type II audited endpoint surface
SOAR / XDR 14 playbooks

Pre-built playbooks for Tines, Torq, Cortex XSOAR.

Fourteen plug-and-play playbook packs translate a confirmed zero-day advisory into containment actions — host isolation, IOC blocklists, EDR sweep, identity-revocation — without an analyst writing a single line.

  • Containment in under 90 seconds end-to-end
  • Compatible with XDR vendors 1–14 on the latest index
  • Tested against the 2024 Cyber Defense rubric
// 05 — APT CROSS-REFERENCE

Every CVE has a fingerprint. Most feeds don't carry it.

Cross-reference 1,840+ cataloged vulnerabilities against 312 named Chinese-nexus APT groups and gray-market exploit vendors — the relationship graph that turns a CVE alert into a who, a how, and a why-it-matters. Four samples below from the live index.

Shanghai skyline layered with fiber-optic infrastructure, duotone red treatment
APT APT-31 / Zirconium

Zirconium

Active since 2012 · 47 linked CVEs · 6 exploit families

Long-running espionage cluster tied to Microsoft, Google, and HPE disclosures. Database carries every one of their public exploit families back to 2018 with the IOC bundle pre-staged for Splunk and Sentinel.

Industrial control room with server racks, red duotone
VENDOR i-Soon / Anxun Information

Anxun (i-Soon)

Gray-market vendor · 23 linked CVEs · 4 exploit families

Tracked since the 2024 leak corpus. Every CVE Anxun resold to MSS-adjacent buyers is fingerprinted in the database with the original exploit author, the resale chain, and a confidence rating.

Undersea fiber-optic cable bundles entering a Shanghai data center, duotone
APT Mustang Panda / Bronze President

Mustang Panda

Active since 2014 · 38 linked CVEs · 9 exploit families

Southeast Asian and EU diplomatic targeting. The database resolves each linked CVE to a specific PlugX, KorPlug, or ToneShell variant, with the implant's TTPs cross-walked to ATT&CK.

Research lab with monitor arrays, red duotone, silhouettes only
RESEARCHER cigarettesmoker / 192.in

Independent Broker Cluster

Tracked since 2020 · 61 linked CVEs · 12 exploit families

A gray-market broker cluster brokering exclusive access to N-day and zero-day exploits sourced from Chinese independent researchers. Each linked CVE carries a non-attribution caveat and a confidence rating.

// 06 — METHODOLOGY

How we keep the database honest.

ZeroDayCN's catalog is sourced from four primary channels: an in-house honeypot array spanning 14 ISPs across mainland China and three Southeast Asian PoPs; a private sandbox cluster running daily triage of suspicious samples submitted by enterprise subscribers; a responsible-disclosure intake that has coordinated 230+ vendor patches with Microsoft, Apple, Google, and Huawei security teams; and direct research output from the team's 11 senior vulnerability researchers — alumni of Qihoo 360, NSFocus, and Pangu Lab with 140+ years of combined experience.

Each candidate CVE passes a four-stage validation pipeline before publication. First, a static and dynamic analysis pass against the in-house sandbox to confirm exploitability and reproducibility. Second, a vendor-notification handshake — we hold publication until the vendor has confirmed or 72 hours have elapsed, whichever comes first. Third, a peer review by at least two senior researchers outside the original discoverer. Fourth, a confidence rating from 1 to 5 with the rationale recorded in the advisory metadata. We cite our false-positive rate at 4.7% across the 1,840+ cataloged entries in 2024 — not zero, because zero is a lie your SOC team would catch inside a week.

The cross-reference layer between CVEs and the 312 tracked Chinese-nexus APT and gray-market exploit vendors is built and maintained by a separate team of 6 threat intelligence analysts, with attribution confidence scores reviewed quarterly. We do not assert state affiliation beyond what open-source reporting already supports, and we do not publish exploit binaries, weaponized proof-of-concept code, or hacking-as-a-service offerings. What we publish is validated intelligence — the kind that survives a SOC2 audit and a procurement review.

SIGNED ZeroDayCN Research Desk Shanghai · Updated quarterly
4.7% cited false-positive rate