Skip to content
COOEY

FAIL › dossier

Multiple Products

PRODUCT

· dossier confidence 40%

QXO, Inc. is a publicly traded building materials distributor with no internal security failures in the provided evidence. The CVE list contains unrelated vendors and products.

PROFILE
CategoryBuilding Materials DistributorWhat they doQXO, Inc. is a leading distributor and installer of building products in North America, specializing in insulation, roofing, lumber, and waterproofing materials.Ownershippublic Websitehttps://www.qxo.com ↗
SECURITY POSTURE

No internal failure history provided for QXO, Inc. in the supplied evidence; the CVE list contains unrelated vendors (Apple, Fortinet, Cleo, etc.).

FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-04-25 CVE-2022-29464 critical WSO2 products have a critical vulnerability allowing unrestricted file uploads and remote code execution, actively exploited in ransomware attacks.
2024-12-17 CVE-2024-55956 critical Cleo's managed file transfer products allowed unauthenticated attackers to upload and execute arbitrary commands via an Autorun directory vulnerability.
2024-12-13 CVE-2024-50623 critical Cleo's managed file transfer products suffered an unrestricted file upload vulnerability enabling remote code execution with elevated privileges.
2024-11-21 CVE-2024-44308 high Apple devices are actively exploited via a remote code execution vulnerability in web content processing.
2024-10-09 CVE-2024-23113 high Fortinet products allow remote, unauthenticated attackers to execute arbitrary code via a format string vulnerability.
2024-03-06 CVE-2024-23296 high Apple's RTKit on iOS/macOS allows kernel memory bypass enabling arbitrary code execution.
2024-03-06 CVE-2024-23225 high Apple's iOS/macOS kernels contain a memory corruption vulnerability allowing arbitrary kernel read/write access, enabling attackers to bypass kernel protections.
2022-10-11 CVE-2022-40684 critical An unauthenticated attacker could bypass authentication on Fortinet FortiOS, FortiProxy, and FortiSwitchManager via crafted HTTP/HTTPS requests, enabling administrative operations.
2022-10-24 CVE-2018-19320 critical GIGABYTE drivers exposed ring0 memcpy functionality allowing local attackers to take full system control.
2022-10-24 CVE-2018-19322 critical GIGABYTE low-level drivers in multiple products allowed remote code execution via IO port access, leading to ransomware exploitation.
2022-10-24 CVE-2018-19323 critical GIGABYTE drivers allow local privilege escalation via arbitrary memory read/write, enabling ransomware attackers to gain system control.
2022-10-24 CVE-2018-19321 critical GIGABYTE drivers allowed local privilege escalation via arbitrary memory read/write, enabling ransomware entry.
2022-05-23 CVE-2021-30883 high Apple's iOS, macOS, watchOS, and tvOS suffered a memory corruption vulnerability enabling remote code execution.
2022-05-04 CVE-2021-1789 high A type confusion vulnerability in multiple Apple products allowed arbitrary code execution via malicious web content.
2022-05-04 CVE-2019-8506 high A type confusion vulnerability in multiple Apple products allowed arbitrary code execution via malicious web content.
2022-05-23 CVE-2019-7286 high Apple's iOS, macOS, watchOS, and tvOS suffered a memory corruption vulnerability allowing privilege escalation that was actively exploited in the wild.
2026-03-05 CVE-2017-7921 high Hikvision products had unpatched, exploited improper authentication vulns.
2026-03-05 CVE-2021-22681 high Rockwell's Studio 5000 Logix Designer exposed key to unauthorized access to Logix controllers.
2026-03-05 CVE-2021-30952 high Apple's tvOS, macOS, Safari, iPadOS, and watchOS suffered an integer overflow or wraparound vulnerability, allowing arbitrary code execution via malicious web content.
2026-03-05 CVE-2023-43000 high Apple's macOS, iOS, iPadOS, and Safari versions 16.6 suffer from a Use-After-Free vulnerability exploited in the wild.
2026-02-12 CVE-2026-20700 high Apple iOS, macOS, tvOS, watchOS, and visionOS contain buffer overflow vulnerabilities that could allow arbitrary code execution.
2026-01-27 CVE-2026-24858 high Fortinet's multiple products suffered an authentication bypass allowing unauthorized access via FortiCloud SSO.
2025-12-17 CVE-2025-20393 high Cisco gear with AsyncOS, Web Manager, and Secure Email suffered remote code execution due to improper input validation, allowing root access on affected systems.
2025-12-16 CVE-2025-59718 high Fortinet products allow unauthenticated attackers to bypass authentication via crafted SAML messages
2025-12-15 CVE-2025-43529 high Apple products affected by unpatched use-after-free vulnerability in WebKit.
2025-10-20 CVE-2022-48503 high Apple products with macOS, iOS, tvOS, Safari, and watchOS may allow arbitrary code execution due to an unspecified vulnerability in JavaScriptCore.
2025-10-06 CVE-2010-3765 high Mozilla Firefox, SeaMonkey, and Thunderbird exposed to remote code execution due to unpatched memory corruption issues.
2025-09-04 CVE-2025-53690 high Sitecore's deserialization flaw allowed remote code execution via untrusted data processing
2025-06-16 CVE-2025-43200 high Apple iOS, iPadOS, macOS, watchOS, and visionOS contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
2025-05-14 CVE-2025-32756 high Fortinet products have a stack-based buffer overflow allowing remote code execution without authentication, and are currently being exploited in the wild.
2025-03-13 CVE-2025-24201 high A WebKit out-of-bounds write vulnerability in Apple products allows malicious web content to escape the sandbox, actively exploited in the wild and impacting DIB organizations using Apple devices or WebKit-dependent software.
2023-09-25 CVE-2023-41991 high Apple iOS, iPadOS, macOS, and watchOS improper certificate validation vulnerability
2023-09-25 CVE-2023-41992 high Apple iOS, iPadOS, macOS, and watchOS kernel privilege escalation vulnerability
2023-09-25 CVE-2023-41993 high Apple WebKit vulnerability allows code execution via malicious web content.
2023-06-23 CVE-2023-32434 high An integer overflow vulnerability in Apple's operating systems allows applications to potentially execute code with kernel privileges, and is currently being exploited in the wild.
2023-06-23 CVE-2023-32439 high WebKit Type Confusion Vulnerability in Apple products allows remote code execution.
2023-05-22 CVE-2023-28204 high Apple WebKit out-of-bounds read vulnerability
2023-05-22 CVE-2023-32373 high Apple WebKit Use-After-Free Vulnerability enables code execution.
2023-05-22 CVE-2023-32409 high WebKit sandbox escape vulnerability in Apple products allows remote code execution.
2023-05-12 CVE-2023-25717 high Ruckus Wireless CSRF and RCE vulnerability allows remote code execution.
2023-04-10 CVE-2023-28205 high Apple's Safari and macOS WebKit vulnerable to code execution via malicious web content.
2023-02-14 CVE-2023-23529 high Apple's Safari and iPadOS WebKit vulnerable to code execution via malicious web content
2023-02-02 CVE-2023-22952 high SugarCRM's EmailTemplates RCE flaw exploited in wild
2022-08-18 CVE-2022-22536 high SAP's NetWeaver products exploited for HTTP request smuggling
2022-06-27 CVE-2020-3837 high A memory corruption vulnerability in Apple's operating systems allowed applications to potentially execute code with kernel privileges, and was actively exploited in the wild.
2022-06-27 CVE-2019-8605 high Apple products suffered from a use-after-free vulnerability actively exploited in the wild, potentially allowing code execution with system privileges.
2022-06-27 CVE-2020-9907 high Apple's iOS, iPadOS, and tvOS products contained a memory corruption vulnerability actively exploited in the wild, allowing code execution with kernel privileges.
2025-04-17 CVE-2025-31200 high A memory corruption vulnerability in Apple products allows code execution via malicious audio files, and is currently being exploited in the wild.
2024-01-31 CVE-2022-48618 high Apple devices are vulnerable to a TOCTOU memory corruption flaw that bypasses Pointer Authentication, allowing attackers to bypass security controls on iOS, macOS, and other platforms.
2023-12-04 CVE-2023-42917 high A WebKit memory corruption vulnerability in Apple products allows for code execution via malicious web content, and is currently being exploited in the wild.
2023-07-13 CVE-2023-37450 high A WebKit vulnerability in Apple products allows for arbitrary code execution via malicious web content, and is currently being exploited in the wild.
2023-06-23 CVE-2023-32435 high A WebKit memory corruption vulnerability in Apple products allows for code execution via malicious web content, and is currently being exploited in the wild.
2022-06-27 CVE-2018-4344 high A memory corruption vulnerability in Apple's operating systems allowed for code execution and is currently being exploited in the wild.
2022-04-15 CVE-2019-3929 high Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
2021-11-03 CVE-2020-2555 high Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle R
2021-11-03 CVE-2020-4006 high VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator accou
2021-11-03 CVE-2021-30860 high Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.
2021-11-03 CVE-2020-27930 high Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.
2021-11-03 CVE-2021-30661 high Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple
2021-11-03 CVE-2021-30665 high Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and n
Open questions: What is QXO, Inc.'s founding year? · What is QXO, Inc.'s headquarters location? · What is QXO, Inc.'s company size? · What is QXO, Inc.'s ownership structure? · What is QXO, Inc.'s website URL? · What is QXO, Inc.'s security posture and failure history?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:01:55.442460+00:00