PatchSiren

Quanta Computer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Quanta Computer CVE published 2026-01-05

CVE-2025-15240

CVE-2025-15240 debrief based on the supplied source corpus. The QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. This vulnerability has a high severity with a CVSS score of 8.7. Defenders should prioritize ver [truncated]

HIGH Quanta Computer CVE published 2026-01-05

CVE-2025-15239

CVE-2025-15239 debrief based on the supplied source corpus. The CVE record was published on 2026-01-05T09:15:54.027Z and has not been modified since then. The QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. Defenders responsible for QOCA aim AI Medical Clou [truncated]

HIGH Quanta Computer CVE published 2026-01-05

CVE-2025-15238

CVE-2025-15238 is a SQL Injection vulnerability in QOCA aim AI Medical Cloud Platform developed by Quanta Computer. An authenticated remote attacker can inject arbitrary SQL commands to read database contents. The CVSS score is 7.1, indicating a HIGH severity vulnerability. This vulnerability allows attackers to potentially access sensitive database information, which could lead to data breaches or unauth [truncated]

MEDIUM Quanta Computer CVE published 2026-01-05

CVE-2025-15237

CVE-2025-15237 debrief based on the supplied source corpus. The CVE record was published on 2026-01-05T08:15:57.620Z and has not been modified since then. The QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability. Defende [truncated]

MEDIUM Quanta Computer CVE published 2026-01-05

CVE-2025-15236

CVE-2025-15236 is a Path Traversal vulnerability in QOCA aim AI Medical Cloud Platform developed by Quanta Computer. Authenticated remote attackers can exploit an Absolute Path Traversal vulnerability to read folder names under the specified path. This vulnerability has a medium severity and requires attention from system administrators and security teams. The affected product is QOCA aim AI Medical Cloud [truncated]

HIGH Quanta Computer CVE published 2026-01-05

CVE-2025-15235

The QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability. This vulnerability allows authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files. The vulnerability is described as a CWE-862 weakness. Defenders should assess exposure and prioritize remediation to prevent unaut [truncated]