CVEs from 2008 known to be exploited
Entries6
Ransomware-linked1
Avg. lag16.0 yrs
Year added to KEV
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2008-4128 | Cisco IOS | 2026-07-13 | 33.8% | Unknown |
| CVE-2008-4250 | Microsoft Windows | 2026-05-20 | 98.7% | Unknown |
| CVE-2008-0015 | Microsoft Windows | 2026-02-17 | 76.5% | Unknown |
| CVE-2008-0655 | Adobe Acrobat and Reader | 2022-06-08 | 37.8% | Unknown |
| CVE-2008-3431 | Oracle VirtualBox | 2022-03-03 | 6.8% | Unknown |
| CVE-2008-2992 | Adobe Acrobat and Reader | 2022-03-03 | 98.4% | Known |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
6 CVE-2008 vulnerabilities are in KEV; on average they were listed 16.0 years after the CVE year.