Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yandex N.V.

First CVE: Jun 28, 2007Active for: 19 yearsTotal CVEs: 31
33.6
VTI Score
Medium

Yandex N.V. maintains a modestly represented vulnerability footprint concentrated in its browser, communication, and natural-language processing products, where the exposure reflects the complexity of web rendering and user-input handling. The recurring weakness classes center on input-neutralization and output-encoding flaws, including cross-site scripting, improper escaping, and input-validation issues that are characteristic of web-facing and text-processing applications. Defenders tracking this vendor should prioritize Yandex Browser as the primary affected product line and focus on patching cycles for web-platform vulnerabilities. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yandex N.V. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 28, 2007
19 years ago
Most Recent CVE
Dec 9, 2025
231 days ago

Self-Reporting Analysis

Of all the CVEs published by Yandex N.V. as a CNA, 64.9% affect products that Yandex N.V. develops as a vendor.

64.9%
35.1%
Self-reported: 24 (64.9%)
Third-party: 13 (35.1%)

Of all the CVEs published that affect products developed by Yandex N.V., 77.4% are self-published by Yandex N.V. as a CNA.

77.4%
22.6%
Self-published: 24 (77.4%)
Other CNAs: 7 (22.6%)

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-25261HIGH
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through
Jun 15, 20227.826NONO
CVE-2023-26226CRITICAL
A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682
May 30, 20259.825NONO
CVE-2021-25263HIGH
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through
Aug 17, 20217.825NONO
CVE-2016-8503HIGH
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resourc
Oct 26, 20167.325NONO
CVE-2016-8502HIGH
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-reso
Oct 26, 20167.325NONO
CVE-2012-2941MEDIUM
Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter.
May 27, 20124.325NOYES
CVE-2025-5471HIGH
Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affects Telemost: before 2.19.1.
Dec 9, 20257.824NONO
CVE-2024-6473HIGH
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
Sep 3, 20247.824NONO
CVE-2022-28226HIGH
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through
Jun 15, 20227.824NONO
CVE-2020-27969HIGH
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
Sep 13, 20217.324NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
45%
52%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (32.3%)
Network19 (61.3%)
Unknown2 (6.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (87.1%)
High2 (6.5%)
Unknown2 (6.5%)
User Interaction
None16 (51.6%)
Unknown2 (6.5%)
Required13 (41.9%)
Privileges Required
Low6 (19.4%)
High1 (3.2%)
None22 (71.0%)
Unknown2 (6.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yandex N.V..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yandex N.V. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yandex N.V.'s Products

View all 5 CNAs →

Top CWEs