FAIL › dossier
Multiple Products
PRODUCT· dossier confidence 40%
QXO, Inc. is a publicly traded building materials distributor with no internal security failures in the provided evidence. The CVE list contains unrelated vendors and products.
PROFILE
CategoryBuilding Materials DistributorWhat they doQXO, Inc. is a leading distributor and installer of building products in North America, specializing in insulation, roofing, lumber, and waterproofing materials.Ownershippublic
Websitehttps://www.qxo.com ↗
SECURITY POSTURE
No internal failure history provided for QXO, Inc. in the supplied evidence; the CVE list contains unrelated vendors (Apple, Fortinet, Cleo, etc.).
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-25 | CVE-2022-29464 | critical | WSO2 products have a critical vulnerability allowing unrestricted file uploads and remote code execution, actively exploited in ransomware attacks. |
| 2024-12-17 | CVE-2024-55956 | critical | Cleo's managed file transfer products allowed unauthenticated attackers to upload and execute arbitrary commands via an Autorun directory vulnerability. |
| 2024-12-13 | CVE-2024-50623 | critical | Cleo's managed file transfer products suffered an unrestricted file upload vulnerability enabling remote code execution with elevated privileges. |
| 2024-11-21 | CVE-2024-44308 | high | Apple devices are actively exploited via a remote code execution vulnerability in web content processing. |
| 2024-10-09 | CVE-2024-23113 | high | Fortinet products allow remote, unauthenticated attackers to execute arbitrary code via a format string vulnerability. |
| 2024-03-06 | CVE-2024-23296 | high | Apple's RTKit on iOS/macOS allows kernel memory bypass enabling arbitrary code execution. |
| 2024-03-06 | CVE-2024-23225 | high | Apple's iOS/macOS kernels contain a memory corruption vulnerability allowing arbitrary kernel read/write access, enabling attackers to bypass kernel protections. |
| 2022-10-11 | CVE-2022-40684 | critical | An unauthenticated attacker could bypass authentication on Fortinet FortiOS, FortiProxy, and FortiSwitchManager via crafted HTTP/HTTPS requests, enabling administrative operations. |
| 2022-04-15 | CVE-2019-3929 | high | Crestron products allow remote, unauthenticated attackers to execute OS commands as root via command injection on the file_transfer.cgi endpoint. |
| 2021-11-03 | CVE-2021-30661 | high | Apple's WebKit use-after-free flaw in iOS/macOS Safari allowed remote code execution via malicious web content. |
| 2021-11-03 | CVE-2020-9859 | high | Apple's iOS, iPadOS, macOS, watchOS, and tvOS suffered a kernel privilege escalation vulnerability allowing arbitrary code execution. |
| 2021-11-03 | CVE-2020-2555 | high | Unauthenticated remote code execution flaw in multiple Oracle products allowed attackers to take over systems via T3 or HTTP. |
| 2021-11-03 | CVE-2021-30807 | high | Apple's IOMobileFrameBuffer memory corruption flaw allowed kernel privilege escalation via user-space apps. |
| 2022-10-24 | CVE-2018-19323 | critical | GIGABYTE drivers allow local privilege escalation via arbitrary memory read/write, enabling ransomware attackers to gain system control. |
| 2022-10-24 | CVE-2018-19321 | critical | GIGABYTE drivers allowed local privilege escalation via arbitrary memory read/write, enabling ransomware entry. |
| 2022-10-24 | CVE-2018-19320 | critical | GIGABYTE drivers exposed ring0 memcpy functionality allowing local attackers to take full system control. |
| 2022-10-24 | CVE-2018-19322 | critical | GIGABYTE low-level drivers in multiple products allowed remote code execution via IO port access, leading to ransomware exploitation. |
| 2022-05-23 | CVE-2021-30883 | high | Apple's iOS, macOS, watchOS, and tvOS suffered a memory corruption vulnerability enabling remote code execution. |
| 2022-05-04 | CVE-2019-8506 | high | A type confusion vulnerability in multiple Apple products allowed arbitrary code execution via malicious web content. |
| 2022-05-04 | CVE-2021-1789 | high | A type confusion vulnerability in multiple Apple products allowed arbitrary code execution via malicious web content. |
| 2021-11-03 | CVE-2021-1782 | high | A race condition in Apple's iOS, iPadOS, macOS, watchOS, and tvOS allowed malicious apps to elevate privileges, and the vulnerability was actively exploited in the wild. |
| 2021-11-03 | CVE-2021-30663 | high | WebKit integer overflow in Apple products allows remote code execution via malicious web content. |
| 2021-11-03 | CVE-2021-30665 | high | Apple's WebKit memory corruption flaw in iOS, macOS, and other OSes allows remote code execution via malicious web content. |
| 2021-11-03 | CVE-2020-27932 | high | Apple's type confusion vulnerability in iOS, iPadOS, macOS, and watchOS allowed malicious apps to execute kernel-level code. |
| 2021-11-03 | CVE-2020-27950 | high | Apple's memory initialization flaw in iOS, iPadOS, macOS, and watchOS allowed malicious apps to leak kernel memory, and it was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-27930 | high | Apple's FontParser memory corruption flaw in iOS, iPadOS, macOS, and watchOS allowed remote code execution when processing malicious fonts. |
| 2021-11-03 | CVE-2021-30860 | high | Apple's CoreGraphics integer overflow vulnerability (CVE-2021-30860) allowed remote code execution via malicious PDFs across iOS, iPadOS, macOS, and watchOS. |
| 2021-11-03 | CVE-2020-29583 | high | Zyxel firewalls and AP controllers shipped with an unchangeable hard-coded credential in an undocumented account. |
| 2021-11-03 | CVE-2020-4006 | high | Command injection flaw in VMware Workspace One products allowed attackers with admin access to execute unrestricted OS commands. |
| 2021-11-03 | CVE-2020-3950 | high | Improper use of setuid binaries in VMware Fusion, VMRC, and Horizon Client for Mac allowed privilege escalation to root. |
| 2022-05-23 | CVE-2019-7286 | high | Apple's iOS, macOS, watchOS, and tvOS suffered a memory corruption vulnerability allowing privilege escalation that was actively exploited in the wild. |
| 2026-03-05 | CVE-2017-7921 | high | Hikvision products had unpatched, exploited improper authentication vulns. |
| 2026-03-05 | CVE-2021-30952 | high | Apple's tvOS, macOS, Safari, iPadOS, and watchOS suffered an integer overflow or wraparound vulnerability, allowing arbitrary code execution via malicious web content. |
| 2026-03-05 | CVE-2021-22681 | high | Rockwell's Studio 5000 Logix Designer exposed key to unauthorized access to Logix controllers. |
| 2026-03-05 | CVE-2023-43000 | high | Apple's macOS, iOS, iPadOS, and Safari versions 16.6 suffer from a Use-After-Free vulnerability exploited in the wild. |
| 2026-02-12 | CVE-2026-20700 | high | Apple iOS, macOS, tvOS, watchOS, and visionOS contain buffer overflow vulnerabilities that could allow arbitrary code execution. |
| 2026-01-27 | CVE-2026-24858 | high | Fortinet's multiple products suffered an authentication bypass allowing unauthorized access via FortiCloud SSO. |
| 2025-12-17 | CVE-2025-20393 | high | Cisco gear with AsyncOS, Web Manager, and Secure Email suffered remote code execution due to improper input validation, allowing root access on affected systems. |
| 2025-12-16 | CVE-2025-59718 | high | Fortinet products allow unauthenticated attackers to bypass authentication via crafted SAML messages |
| 2025-12-15 | CVE-2025-43529 | high | Apple products affected by unpatched use-after-free vulnerability in WebKit. |
| 2025-10-20 | CVE-2022-48503 | high | Apple products with macOS, iOS, tvOS, Safari, and watchOS may allow arbitrary code execution due to an unspecified vulnerability in JavaScriptCore. |
| 2025-10-06 | CVE-2010-3765 | high | Mozilla Firefox, SeaMonkey, and Thunderbird exposed to remote code execution due to unpatched memory corruption issues. |
| 2025-09-04 | CVE-2025-53690 | high | Sitecore's deserialization flaw allowed remote code execution via untrusted data processing |
| 2025-06-16 | CVE-2025-43200 | high | Apple iOS, iPadOS, macOS, watchOS, and visionOS contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link. |
| 2025-05-14 | CVE-2025-32756 | high | Fortinet products have a stack-based buffer overflow allowing remote code execution without authentication, and are currently being exploited in the wild. |
| 2025-03-13 | CVE-2025-24201 | high | A WebKit out-of-bounds write vulnerability in Apple products allows malicious web content to escape the sandbox, actively exploited in the wild and impacting DIB organizations using Apple devices or WebKit-dependent software. |
| 2023-09-25 | CVE-2023-41991 | high | Apple iOS, iPadOS, macOS, and watchOS improper certificate validation vulnerability |
| 2023-09-25 | CVE-2023-41992 | high | Apple iOS, iPadOS, macOS, and watchOS kernel privilege escalation vulnerability |
| 2023-09-25 | CVE-2023-41993 | high | Apple WebKit vulnerability allows code execution via malicious web content. |
| 2023-06-23 | CVE-2023-32434 | high | An integer overflow vulnerability in Apple's operating systems allows applications to potentially execute code with kernel privileges, and is currently being exploited in the wild. |
| 2023-06-23 | CVE-2023-32439 | high | WebKit Type Confusion Vulnerability in Apple products allows remote code execution. |
| 2023-05-22 | CVE-2023-32373 | high | Apple WebKit Use-After-Free Vulnerability enables code execution. |
| 2023-05-22 | CVE-2023-32409 | high | WebKit sandbox escape vulnerability in Apple products allows remote code execution. |
| 2023-05-22 | CVE-2023-28204 | high | Apple WebKit out-of-bounds read vulnerability |
| 2023-05-12 | CVE-2023-25717 | high | Ruckus Wireless CSRF and RCE vulnerability allows remote code execution. |
| 2023-04-10 | CVE-2023-28205 | high | Apple's Safari and macOS WebKit vulnerable to code execution via malicious web content. |
| 2023-02-14 | CVE-2023-23529 | high | Apple's Safari and iPadOS WebKit vulnerable to code execution via malicious web content |
| 2023-02-02 | CVE-2023-22952 | high | SugarCRM's EmailTemplates RCE flaw exploited in wild |
| 2022-08-18 | CVE-2022-22536 | high | SAP's NetWeaver products exploited for HTTP request smuggling |
| 2022-06-27 | CVE-2020-3837 | high | A memory corruption vulnerability in Apple's operating systems allowed applications to potentially execute code with kernel privileges, and was actively exploited in the wild. |
DOSSIER SOURCES
- QXO, Inc. (QXO) Company Profile & Description - Stock Analysis · stockanalysis.com
- How CIOs Build Organizations That Scale: Architecture ... - LinkedIn · www.linkedin.com
- QXO (QXO) Company Profile, History, Products & Services · www.financecharts.com
- QXO, Inc. - Investor Relations · investors.qxo.com
- QXO's War Chest Up to $5B After Another Private Placement · www.mdm.com
Open questions: What is QXO, Inc.'s founding year? · What is QXO, Inc.'s headquarters location? · What is QXO, Inc.'s company size? · What is QXO, Inc.'s ownership structure? · What is QXO, Inc.'s website URL? · What is QXO, Inc.'s security posture and failure history?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:01:55.442460+00:00