FAIL › dossier
Multiple Products
PRODUCT· dossier confidence 40%
QXO, Inc. is a publicly traded building materials distributor with no internal security failures in the provided evidence. The CVE list contains unrelated vendors and products.
PROFILE
CategoryBuilding Materials DistributorWhat they doQXO, Inc. is a leading distributor and installer of building products in North America, specializing in insulation, roofing, lumber, and waterproofing materials.Ownershippublic
Websitehttps://www.qxo.com ↗
SECURITY POSTURE
No internal failure history provided for QXO, Inc. in the supplied evidence; the CVE list contains unrelated vendors (Apple, Fortinet, Cleo, etc.).
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-25 | CVE-2022-29464 | critical | WSO2 products have a critical vulnerability allowing unrestricted file uploads and remote code execution, actively exploited in ransomware attacks. |
| 2024-12-17 | CVE-2024-55956 | critical | Cleo's managed file transfer products allowed unauthenticated attackers to upload and execute arbitrary commands via an Autorun directory vulnerability. |
| 2024-12-13 | CVE-2024-50623 | critical | Cleo's managed file transfer products suffered an unrestricted file upload vulnerability enabling remote code execution with elevated privileges. |
| 2024-11-21 | CVE-2024-44308 | high | Apple devices are actively exploited via a remote code execution vulnerability in web content processing. |
| 2024-10-09 | CVE-2024-23113 | high | Fortinet products allow remote, unauthenticated attackers to execute arbitrary code via a format string vulnerability. |
| 2024-03-06 | CVE-2024-23296 | high | Apple's RTKit on iOS/macOS allows kernel memory bypass enabling arbitrary code execution. |
| 2024-03-06 | CVE-2024-23225 | high | Apple's iOS/macOS kernels contain a memory corruption vulnerability allowing arbitrary kernel read/write access, enabling attackers to bypass kernel protections. |
| 2022-10-11 | CVE-2022-40684 | critical | An unauthenticated attacker could bypass authentication on Fortinet FortiOS, FortiProxy, and FortiSwitchManager via crafted HTTP/HTTPS requests, enabling administrative operations. |
| 2022-10-24 | CVE-2018-19320 | critical | GIGABYTE drivers exposed ring0 memcpy functionality allowing local attackers to take full system control. |
| 2022-10-24 | CVE-2018-19322 | critical | GIGABYTE low-level drivers in multiple products allowed remote code execution via IO port access, leading to ransomware exploitation. |
| 2022-10-24 | CVE-2018-19323 | critical | GIGABYTE drivers allow local privilege escalation via arbitrary memory read/write, enabling ransomware attackers to gain system control. |
| 2022-10-24 | CVE-2018-19321 | critical | GIGABYTE drivers allowed local privilege escalation via arbitrary memory read/write, enabling ransomware entry. |
| 2022-05-23 | CVE-2021-30883 | high | Apple's iOS, macOS, watchOS, and tvOS suffered a memory corruption vulnerability enabling remote code execution. |
| 2022-05-04 | CVE-2021-1789 | high | A type confusion vulnerability in multiple Apple products allowed arbitrary code execution via malicious web content. |
| 2022-05-04 | CVE-2019-8506 | high | A type confusion vulnerability in multiple Apple products allowed arbitrary code execution via malicious web content. |
| 2022-05-23 | CVE-2019-7286 | high | Apple's iOS, macOS, watchOS, and tvOS suffered a memory corruption vulnerability allowing privilege escalation that was actively exploited in the wild. |
| 2026-03-05 | CVE-2017-7921 | high | Hikvision products had unpatched, exploited improper authentication vulns. |
| 2026-03-05 | CVE-2021-22681 | high | Rockwell's Studio 5000 Logix Designer exposed key to unauthorized access to Logix controllers. |
| 2026-03-05 | CVE-2021-30952 | high | Apple's tvOS, macOS, Safari, iPadOS, and watchOS suffered an integer overflow or wraparound vulnerability, allowing arbitrary code execution via malicious web content. |
| 2026-03-05 | CVE-2023-43000 | high | Apple's macOS, iOS, iPadOS, and Safari versions 16.6 suffer from a Use-After-Free vulnerability exploited in the wild. |
| 2026-02-12 | CVE-2026-20700 | high | Apple iOS, macOS, tvOS, watchOS, and visionOS contain buffer overflow vulnerabilities that could allow arbitrary code execution. |
| 2026-01-27 | CVE-2026-24858 | high | Fortinet's multiple products suffered an authentication bypass allowing unauthorized access via FortiCloud SSO. |
| 2025-12-17 | CVE-2025-20393 | high | Cisco gear with AsyncOS, Web Manager, and Secure Email suffered remote code execution due to improper input validation, allowing root access on affected systems. |
| 2025-12-16 | CVE-2025-59718 | high | Fortinet products allow unauthenticated attackers to bypass authentication via crafted SAML messages |
| 2025-12-15 | CVE-2025-43529 | high | Apple products affected by unpatched use-after-free vulnerability in WebKit. |
| 2025-10-20 | CVE-2022-48503 | high | Apple products with macOS, iOS, tvOS, Safari, and watchOS may allow arbitrary code execution due to an unspecified vulnerability in JavaScriptCore. |
| 2025-10-06 | CVE-2010-3765 | high | Mozilla Firefox, SeaMonkey, and Thunderbird exposed to remote code execution due to unpatched memory corruption issues. |
| 2025-09-04 | CVE-2025-53690 | high | Sitecore's deserialization flaw allowed remote code execution via untrusted data processing |
| 2025-06-16 | CVE-2025-43200 | high | Apple iOS, iPadOS, macOS, watchOS, and visionOS contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link. |
| 2025-05-14 | CVE-2025-32756 | high | Fortinet products have a stack-based buffer overflow allowing remote code execution without authentication, and are currently being exploited in the wild. |
| 2025-03-13 | CVE-2025-24201 | high | A WebKit out-of-bounds write vulnerability in Apple products allows malicious web content to escape the sandbox, actively exploited in the wild and impacting DIB organizations using Apple devices or WebKit-dependent software. |
| 2023-09-25 | CVE-2023-41991 | high | Apple iOS, iPadOS, macOS, and watchOS improper certificate validation vulnerability |
| 2023-09-25 | CVE-2023-41992 | high | Apple iOS, iPadOS, macOS, and watchOS kernel privilege escalation vulnerability |
| 2023-09-25 | CVE-2023-41993 | high | Apple WebKit vulnerability allows code execution via malicious web content. |
| 2023-06-23 | CVE-2023-32434 | high | An integer overflow vulnerability in Apple's operating systems allows applications to potentially execute code with kernel privileges, and is currently being exploited in the wild. |
| 2023-06-23 | CVE-2023-32439 | high | WebKit Type Confusion Vulnerability in Apple products allows remote code execution. |
| 2023-05-22 | CVE-2023-28204 | high | Apple WebKit out-of-bounds read vulnerability |
| 2023-05-22 | CVE-2023-32373 | high | Apple WebKit Use-After-Free Vulnerability enables code execution. |
| 2023-05-22 | CVE-2023-32409 | high | WebKit sandbox escape vulnerability in Apple products allows remote code execution. |
| 2023-05-12 | CVE-2023-25717 | high | Ruckus Wireless CSRF and RCE vulnerability allows remote code execution. |
| 2023-04-10 | CVE-2023-28205 | high | Apple's Safari and macOS WebKit vulnerable to code execution via malicious web content. |
| 2023-02-14 | CVE-2023-23529 | high | Apple's Safari and iPadOS WebKit vulnerable to code execution via malicious web content |
| 2023-02-02 | CVE-2023-22952 | high | SugarCRM's EmailTemplates RCE flaw exploited in wild |
| 2022-08-18 | CVE-2022-22536 | high | SAP's NetWeaver products exploited for HTTP request smuggling |
| 2022-06-27 | CVE-2020-3837 | high | A memory corruption vulnerability in Apple's operating systems allowed applications to potentially execute code with kernel privileges, and was actively exploited in the wild. |
| 2022-06-27 | CVE-2019-8605 | high | Apple products suffered from a use-after-free vulnerability actively exploited in the wild, potentially allowing code execution with system privileges. |
| 2022-06-27 | CVE-2020-9907 | high | Apple's iOS, iPadOS, and tvOS products contained a memory corruption vulnerability actively exploited in the wild, allowing code execution with kernel privileges. |
| 2025-04-17 | CVE-2025-31200 | high | A memory corruption vulnerability in Apple products allows code execution via malicious audio files, and is currently being exploited in the wild. |
| 2024-01-31 | CVE-2022-48618 | high | Apple devices are vulnerable to a TOCTOU memory corruption flaw that bypasses Pointer Authentication, allowing attackers to bypass security controls on iOS, macOS, and other platforms. |
| 2023-12-04 | CVE-2023-42917 | high | A WebKit memory corruption vulnerability in Apple products allows for code execution via malicious web content, and is currently being exploited in the wild. |
| 2023-07-13 | CVE-2023-37450 | high | A WebKit vulnerability in Apple products allows for arbitrary code execution via malicious web content, and is currently being exploited in the wild. |
| 2023-06-23 | CVE-2023-32435 | high | A WebKit memory corruption vulnerability in Apple products allows for code execution via malicious web content, and is currently being exploited in the wild. |
| 2022-06-27 | CVE-2018-4344 | high | A memory corruption vulnerability in Apple's operating systems allowed for code execution and is currently being exploited in the wild. |
| 2022-04-15 | CVE-2019-3929 | high | Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root. |
| 2021-11-03 | CVE-2020-2555 | high | Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle R |
| 2021-11-03 | CVE-2020-4006 | high | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator accou |
| 2021-11-03 | CVE-2021-30860 | high | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. |
| 2021-11-03 | CVE-2020-27930 | high | Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front. |
| 2021-11-03 | CVE-2021-30661 | high | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple |
| 2021-11-03 | CVE-2021-30665 | high | Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and n |
DOSSIER SOURCES
- QXO, Inc. (QXO) Company Profile & Description - Stock Analysis · stockanalysis.com
- How CIOs Build Organizations That Scale: Architecture ... - LinkedIn · www.linkedin.com
- QXO (QXO) Company Profile, History, Products & Services · www.financecharts.com
- QXO, Inc. - Investor Relations · investors.qxo.com
- QXO's War Chest Up to $5B After Another Private Placement · www.mdm.com
Open questions: What is QXO, Inc.'s founding year? · What is QXO, Inc.'s headquarters location? · What is QXO, Inc.'s company size? · What is QXO, Inc.'s ownership structure? · What is QXO, Inc.'s website URL? · What is QXO, Inc.'s security posture and failure history?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:01:55.442460+00:00