Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tcman

First CVE: Dec 17, 2021Active for: 5 yearsTotal CVEs: 24
38.1
VTI Score
Medium

Tcman maintains a narrowly scoped product portfolio centered on the GIM application, which despite modest volume has achieved prominence within its operational domain. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in application-layer weakness classes including SQL injection, authorization bypass, cross-site scripting, and sensitive information exposure—a pattern consistent with web-facing business applications where input validation and access control are foundational. The recurring authorization and input-handling deficiencies suggest that strengthening these controls would materially reduce the vendor's exposure across its portfolio. Defenders should prioritize patching for this vendor given the severity tendency and the authentication and injection risks inherent to these weakness classes; live exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
6.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tcman over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 17, 2021
4 years ago
Most Recent CVE
Dec 2, 2025
233 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-40666CRITICAL
Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in/GIMWeb/PC/f
May 26, 20259.830NONO
CVE-2025-41013CRITICAL
SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request u
Dec 2, 20259.829NONO
CVE-2021-40850CRITICAL
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.
Dec 17, 20219.829NONO
CVE-2025-40621CRITICAL
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi
May 6, 20259.828NONO
CVE-2025-40620CRITICAL
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi
May 6, 20259.828NONO
CVE-2022-36276CRITICAL
TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker
Oct 4, 20239.828NONO
CVE-2025-40665CRITICAL
Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in /GIMWeb/PC/
May 26, 20259.827NONO
CVE-2025-40624CRITICAL
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi
May 6, 20259.827NONO
CVE-2025-40664CRITICAL
Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser
May 26, 20259.126NONO
CVE-2025-40623CRITICAL
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi
May 6, 20259.826NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
29%
21%
50%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (87.5%)
Unknown0 (0.0%)
Required3 (12.5%)
Privileges Required
Low5 (20.8%)
High0 (0.0%)
None19 (79.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tcman.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tcman — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tcman's Products

View all 1 CNAs →

Top CWEs