Yandex N.V. maintains a modestly represented vulnerability footprint concentrated in its browser, communication, and natural-language processing products, where the exposure reflects the complexity of web rendering and user-input handling. The recurring weakness classes center on input-neutralization and output-encoding flaws, including cross-site scripting, improper escaping, and input-validation issues that are characteristic of web-facing and text-processing applications. Defenders tracking this vendor should prioritize Yandex Browser as the primary affected product line and focus on patching cycles for web-platform vulnerabilities. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yandex N.V. over time
Of all the CVEs published by Yandex N.V. as a CNA, 64.9% affect products that Yandex N.V. develops as a vendor.
Of all the CVEs published that affect products developed by Yandex N.V., 77.4% are self-published by Yandex N.V. as a CNA.
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25261HIGH Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through | Jun 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2023-26226CRITICAL A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682 | May 30, 2025 | 9.8 | 25 | NO | NO |
CVE-2021-25263HIGH Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through | Aug 17, 2021 | 7.8 | 25 | NO | NO |
CVE-2016-8503HIGH Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resourc | Oct 26, 2016 | 7.3 | 25 | NO | NO |
CVE-2016-8502HIGH Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-reso | Oct 26, 2016 | 7.3 | 25 | NO | NO |
CVE-2012-2941MEDIUM Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter. | May 27, 2012 | 4.3 | 25 | NO | YES |
CVE-2025-5471HIGH Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affects Telemost: before 2.19.1. | Dec 9, 2025 | 7.8 | 24 | NO | NO |
CVE-2024-6473HIGH Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used. | Sep 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2022-28226HIGH Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through | Jun 15, 2022 | 7.8 | 24 | NO | NO |
CVE-2020-27969HIGH Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing | Sep 13, 2021 | 7.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yandex N.V..
Media articles that mention a CVE ID that affects a product developed by Yandex N.V. — matched by CVE ID, not by vendor name.