Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gim CRITICAL 9.8
CVE-2025-41013

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete datab…

Fix: 2025-04-01+
Fix from $2,300 2025-12-02
Gim HIGH 7.5
CVE-2025-41014

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user e…

Fix: 2025-04-01+
Fix from $1,950 2025-12-02
Gim HIGH 7.5
CVE-2025-41015

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user e…

Fix: 2025-04-01+
Fix from $1,950 2025-12-02
Gim MEDIUM 5.3
CVE-2025-41012

Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a use…

Fix: 2025-04-01+
Fix from $1,600 2025-12-02
Gim HIGH 8.8
CVE-2025-40670

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many priv…

Mitigation only
Fix from $1,950 2025-06-09
Gim MEDIUM 6.5
CVE-2025-40668

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of …

Mitigation only
Fix from $1,600 2025-06-09
Gim MEDIUM 6.5
CVE-2025-40669

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each o…

Mitigation only
Fix from $1,600 2025-06-09
Gim CRITICAL 9.8
CVE-2025-40665

Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through A…

Mitigation only
Fix from $2,300 2025-05-26
Gim CRITICAL 9.8
CVE-2025-40666

Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through A…

Mitigation only
Fix from $2,300 2025-05-26
Gim CRITICAL 9.1
CVE-2025-40664

Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, …

Mitigation only
Fix from $2,300 2025-05-26
Gim MEDIUM 6.5
CVE-2025-40667

Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionality of the application even whe…

Mitigation only
Fix from $1,600 2025-05-26
Gim CRITICAL 9.8
CVE-2025-40623

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…

Mitigation only
Fix from $2,300 2025-05-06
Gim CRITICAL 9.8
CVE-2025-40624

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…

Mitigation only
Fix from $2,300 2025-05-06
Gim CRITICAL 9.8
CVE-2025-40625

Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic…

Mitigation only
Fix from $2,300 2025-05-06
Gim CRITICAL 9.8
CVE-2025-40621

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…

Mitigation only
Fix from $2,300 2025-05-06
Gim CRITICAL 9.8
CVE-2025-40622

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…

Mitigation only
Fix from $2,300 2025-05-06
Gim CRITICAL 9.8
CVE-2025-40620

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…

Mitigation only
Fix from $2,300 2025-05-06
Gim CRITICAL 9.8
CVE-2022-36276

TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerabilit…

Mitigation only
Fix from $2,300 2023-10-04
Gim MEDIUM 6.1
CVE-2022-36277

The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditServicio.aspx files in TCMAN G…

Mitigation only
Fix from $1,600 2023-10-04
Gim MEDIUM 5.4
CVE-2021-4046

The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to ca…

Mitigation only
Fix from $1,600 2022-02-11
Gim CRITICAL 9.8
CVE-2021-40850

TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.

No fix yet
Fix from $2,300 2021-12-17
Gim HIGH 7.5
CVE-2021-40851

TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulner…

Mitigation only
Fix from $1,950 2021-12-17
Gim HIGH 7.2
CVE-2021-40853

TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to a…

Mitigation only
Fix from $1,950 2021-12-17
Gim MEDIUM 6.1
CVE-2021-40852

TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the atta…

Mitigation only
Fix from $1,600 2021-12-17