ZeroHour

Vulnerabilities

24 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-41013
+3 in the same advisory: …41012 …41014 …41015
SQL injection vulnerability in TCMAN GIM v11 in version 20250304.

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

NVD description · AI analysis pending
8.7
group max
<1%
  • tcman gim
CVE-2025-40670
+2 in the same advisory: …40668 …40669
Incorrect authorization vulnerability in TCMAN's GIM v11.

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser.

NVD description · AI analysis pending
7.1<1%
  • tcman gim
CVE-2025-40664
+3 in the same advisory: …40665 …40666 …40667
Missing authentication vulnerability in TCMAN GIM v11.

Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser and /frmGestionUser.aspx/DeleteUser.

NVD description · AI analysis pending
9.3
group max
<1%
  • tcman gim
CVE-2025-40625
Unrestricted file upload in TCMAN's GIM v11.

Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE).

NVD description · AI analysis pending
9.3<1%
  • tcman gim
CVE-2022-36276
+1 in the same advisory: …36277
TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'.

TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database.

NVD description · AI analysis pending
9.8
group max
<1%
  • tcman gim
CVE-2021-4046
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks.

The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.

NVD description · AI analysis pending
5.4<1%
  • tcman gim
CVE-2021-40850
+3 in the same advisory: …40851 …40853 …40852
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.

TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.

NVD description · AI analysis pending
9.8
group max
<1%
  • tcman gim