Yandex N.V.
First CVE: Oct 26, 2016Active for: 10 years
37
CVEs Published
More CVEs Published than 51% of tracked CNAs
4.1
Avg CVEs / Year
More Avg CVEs / Year than 29% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 59% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Yandex N.V. as a CNA, 64.9% affect products that Yandex N.V. develops as a vendor.
64.9%
35.1%
Self-reported: 24Third-party: 13
Of all the CVEs published that affect products developed by Yandex N.V., 77.4% are self-published by Yandex N.V. as a CNA.
77.4%
22.6%
Self-published: 24Published by other CNAs: 7
Trends Over Time
The number and severity of CVEs published by Yandex N.V. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2016
9 years ago
Most Recent CVE
Jun 2, 2026
52 days ago
Top CVEs
All CVEs published by Yandex N.V. as a CNA, regardless of affected vendor or product.
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14671CRITICAL In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability. | Aug 15, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-16535CRITICAL In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol. | Dec 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-14670CRITICAL Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database. | Aug 15, 2019 | 9.8 | 29 | NO | NO |
CVE-2022-28228CRITICAL Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory loca | Dec 23, 2022 | 9.1 | 28 | NO | NO |
CVE-2021-25261HIGH Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through | Jun 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2026-10549MEDIUM LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauth | Jun 2, 2026 | 5.3 | 25 | NO | NO |
CVE-2023-26226CRITICAL A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682 | May 30, 2025 | 9.8 | 25 | NO | NO |
CVE-2021-25263HIGH Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through | Aug 17, 2021 | 7.8 | 25 | NO | NO |
CVE-2018-14668HIGH In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery At | Aug 15, 2019 | 8.8 | 25 | NO | NO |
CVE-2016-8503HIGH Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resourc | Oct 26, 2016 | 7.3 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA37 CVEs
32%
54%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (27.0%)
Network27 (73.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (97.3%)
High1 (2.7%)
Unknown0 (0.0%)
User Interaction
None26 (70.3%)
Unknown0 (0.0%)
Required11 (29.7%)
Privileges Required
Low10 (27.0%)
High0 (0.0%)
None27 (73.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Yandex N.V. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Yandex N.V. as a CNA — matched by CVE ID, not by organization name.