Tcman maintains a narrowly scoped product portfolio centered on the GIM application, which despite modest volume has achieved prominence within its operational domain. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in application-layer weakness classes including SQL injection, authorization bypass, cross-site scripting, and sensitive information exposure—a pattern consistent with web-facing business applications where input validation and access control are foundational. The recurring authorization and input-handling deficiencies suggest that strengthening these controls would materially reduce the vendor's exposure across its portfolio. Defenders should prioritize patching for this vendor given the severity tendency and the authentication and injection risks inherent to these weakness classes; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tcman over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40666CRITICAL Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in/GIMWeb/PC/f | May 26, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-41013CRITICAL SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request u | Dec 2, 2025 | 9.8 | 29 | NO | NO |
CVE-2021-40850CRITICAL TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx. | Dec 17, 2021 | 9.8 | 29 | NO | NO |
CVE-2025-40621CRITICAL SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi | May 6, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-40620CRITICAL SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi | May 6, 2025 | 9.8 | 28 | NO | NO |
CVE-2022-36276CRITICAL TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker | Oct 4, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-40665CRITICAL Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in /GIMWeb/PC/ | May 26, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-40624CRITICAL SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi | May 6, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-40664CRITICAL Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser | May 26, 2025 | 9.1 | 26 | NO | NO |
CVE-2025-40623CRITICAL SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi | May 6, 2025 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tcman.
Media articles that mention a CVE ID that affects a product developed by Tcman — matched by CVE ID, not by vendor name.