Gim
Vendor:
First CVE: Dec 17, 2021 · Active for 4 years
24
Total CVEs
More Total CVEs than 96% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gim over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 17, 2021
4 years ago
Most Recent CVE
Dec 2, 2025
237 days ago
CVE Severity & Scoring
Gim24 CVEs
29%
21%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (87.5%)
Unknown0 (0.0%)
Required3 (12.5%)
Privileges Required
Low5 (20.8%)
High0 (0.0%)
None19 (79.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40666CRITICAL Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in/GIMWeb/PC/f | May 26, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-41013CRITICAL SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request u | Dec 2, 2025 | 9.8 | 29 | NO | NO |
CVE-2021-40850CRITICAL TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx. | Dec 17, 2021 | 9.8 | 29 | NO | NO |
CVE-2025-40621CRITICAL SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi | May 6, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-40620CRITICAL SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi | May 6, 2025 | 9.8 | 28 | NO | NO |
CVE-2022-36276CRITICAL TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker | Oct 4, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-40665CRITICAL Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in /GIMWeb/PC/ | May 26, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-40624CRITICAL SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi | May 6, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-40664CRITICAL Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser | May 26, 2025 | 9.1 | 26 | NO | NO |
CVE-2025-40623CRITICAL SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. Thi | May 6, 2025 | 9.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Gim
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.1 | 3 | 7.1 | 0.5% | 0 | 0 |
| 8.01 | 1 | 5.4 | 0.4% | 0 | 0 |
| 8.0 | 4 | 7.7 | 0.9% | 0 | 0 |
| 11.0 | 17 | 8.6 | 0.5% | 0 | 0 |