CVE-2025-15240 debrief based on the supplied source corpus. The QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. This vulnerability has a high severity with a CVSS score of 8.7. Defenders should prioritize ver [truncated]
CVE-2025-15239 debrief based on the supplied source corpus. The CVE record was published on 2026-01-05T09:15:54.027Z and has not been modified since then. The QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. Defenders responsible for QOCA aim AI Medical Clou [truncated]
CVE-2025-15238 is a SQL Injection vulnerability in QOCA aim AI Medical Cloud Platform developed by Quanta Computer. An authenticated remote attacker can inject arbitrary SQL commands to read database contents. The CVSS score is 7.1, indicating a HIGH severity vulnerability. This vulnerability allows attackers to potentially access sensitive database information, which could lead to data breaches or unauth [truncated]
CVE-2025-15237 debrief based on the supplied source corpus. The CVE record was published on 2026-01-05T08:15:57.620Z and has not been modified since then. The QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability. Defende [truncated]
CVE-2025-15236 is a Path Traversal vulnerability in QOCA aim AI Medical Cloud Platform developed by Quanta Computer. Authenticated remote attackers can exploit an Absolute Path Traversal vulnerability to read folder names under the specified path. This vulnerability has a medium severity and requires attention from system administrators and security teams. The affected product is QOCA aim AI Medical Cloud [truncated]
The QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability. This vulnerability allows authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files. The vulnerability is described as a CWE-862 weakness. Defenders should assess exposure and prioritize remediation to prevent unaut [truncated]