Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dart

First CVE: May 24, 2007Active for: 19 yearsTotal CVEs: 14
36.8
VTI Score
Medium

Dart's vulnerability footprint spans a modestly represented collection of development tools and runtime components, including the Dart SDK, compression utilities, and networking libraries that see deployment across web and application-development contexts. The recurring weakness classes center on memory-safety boundaries, input validation in web contexts, and access control—including buffer-boundary violations, cross-site scripting, and authentication-bypass patterns—and vulnerabilities have an elevated tendency to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dart over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2007
19 years ago
Most Recent CVE
Feb 25, 2026
149 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-4652HIGH
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey
Oct 22, 20089.337NOYES
CVE-2007-2856HIGH
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers
May 24, 20079.336NOYES
CVE-2022-3095CRITICAL
The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC
Oct 27, 20229.830NONO
CVE-2012-3819MEDIUM
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial o
Oct 4, 20125.029NOYES
CVE-2012-5389HIGH
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request.
Jan 23, 20207.528NONO
CVE-2021-22568HIGH
When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publi
Dec 9, 20218.827NONO
CVE-2026-27704HIGH
The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior to version 3.41
Feb 25, 20267.525NONO
CVE-2007-2855HIGH
Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote attackers to execute arbitrary code via
May 24, 20079.324NONO
CVE-2022-0451MEDIUM
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensi
Feb 18, 20226.523NONO
CVE-2020-35669MEDIUM
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF i
Dec 24, 20206.122NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
43%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (71.4%)
Unknown4 (28.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (71.4%)
High0 (0.0%)
Unknown4 (28.6%)
User Interaction
None4 (28.6%)
Unknown4 (28.6%)
Required6 (42.9%)
Privileges Required
Low2 (14.3%)
High0 (0.0%)
None8 (57.1%)
Unknown4 (28.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
21.4% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dart.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dart — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dart's Products

View all 4 CNAs →

Top CWEs