CVEs we hold for Yandex
Records whose assigning authority named Yandex as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-63063WordPress Yandex.Metrica plugin <= 1.2.2 - Broken Access Control vulnerabilityYandex Metrika Yandex.Metrica
CVE-2023-26226A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682Yandex Browser
CVE-2021-25262Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.Yandex Browser
CVE-2021-25255Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.Yandex Browser Lite
CVE-2021-25254Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.Yandex Browser Lite
37 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.