Skip to content
COOEY

FAIL › dossier

Multiple Products

PRODUCT

· dossier confidence 40%

QXO, Inc. is a publicly traded building materials distributor with no internal security failures in the provided evidence. The CVE list contains unrelated vendors and products.

PROFILE
CategoryBuilding Materials DistributorWhat they doQXO, Inc. is a leading distributor and installer of building products in North America, specializing in insulation, roofing, lumber, and waterproofing materials.Ownershippublic Websitehttps://www.qxo.com ↗
SECURITY POSTURE

No internal failure history provided for QXO, Inc. in the supplied evidence; the CVE list contains unrelated vendors (Apple, Fortinet, Cleo, etc.).

FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-04-25 CVE-2022-29464 critical WSO2 products have a critical vulnerability allowing unrestricted file uploads and remote code execution, actively exploited in ransomware attacks.
2024-12-17 CVE-2024-55956 critical Cleo's managed file transfer products allowed unauthenticated attackers to upload and execute arbitrary commands via an Autorun directory vulnerability.
2024-12-13 CVE-2024-50623 critical Cleo's managed file transfer products suffered an unrestricted file upload vulnerability enabling remote code execution with elevated privileges.
2024-11-21 CVE-2024-44308 high Apple devices are actively exploited via a remote code execution vulnerability in web content processing.
2024-10-09 CVE-2024-23113 high Fortinet products allow remote, unauthenticated attackers to execute arbitrary code via a format string vulnerability.
2024-03-06 CVE-2024-23296 high Apple's RTKit on iOS/macOS allows kernel memory bypass enabling arbitrary code execution.
2024-03-06 CVE-2024-23225 high Apple's iOS/macOS kernels contain a memory corruption vulnerability allowing arbitrary kernel read/write access, enabling attackers to bypass kernel protections.
2022-10-11 CVE-2022-40684 critical An unauthenticated attacker could bypass authentication on Fortinet FortiOS, FortiProxy, and FortiSwitchManager via crafted HTTP/HTTPS requests, enabling administrative operations.
2022-04-15 CVE-2019-3929 high Crestron products allow remote, unauthenticated attackers to execute OS commands as root via command injection on the file_transfer.cgi endpoint.
2021-11-03 CVE-2021-30661 high Apple's WebKit use-after-free flaw in iOS/macOS Safari allowed remote code execution via malicious web content.
2021-11-03 CVE-2020-9859 high Apple's iOS, iPadOS, macOS, watchOS, and tvOS suffered a kernel privilege escalation vulnerability allowing arbitrary code execution.
2021-11-03 CVE-2020-2555 high Unauthenticated remote code execution flaw in multiple Oracle products allowed attackers to take over systems via T3 or HTTP.
2021-11-03 CVE-2021-30807 high Apple's IOMobileFrameBuffer memory corruption flaw allowed kernel privilege escalation via user-space apps.
2022-10-24 CVE-2018-19323 critical GIGABYTE drivers allow local privilege escalation via arbitrary memory read/write, enabling ransomware attackers to gain system control.
2022-10-24 CVE-2018-19321 critical GIGABYTE drivers allowed local privilege escalation via arbitrary memory read/write, enabling ransomware entry.
2022-10-24 CVE-2018-19320 critical GIGABYTE drivers exposed ring0 memcpy functionality allowing local attackers to take full system control.
2022-10-24 CVE-2018-19322 critical GIGABYTE low-level drivers in multiple products allowed remote code execution via IO port access, leading to ransomware exploitation.
2022-05-23 CVE-2021-30883 high Apple's iOS, macOS, watchOS, and tvOS suffered a memory corruption vulnerability enabling remote code execution.
2022-05-04 CVE-2019-8506 high A type confusion vulnerability in multiple Apple products allowed arbitrary code execution via malicious web content.
2022-05-04 CVE-2021-1789 high A type confusion vulnerability in multiple Apple products allowed arbitrary code execution via malicious web content.
2021-11-03 CVE-2021-1782 high A race condition in Apple's iOS, iPadOS, macOS, watchOS, and tvOS allowed malicious apps to elevate privileges, and the vulnerability was actively exploited in the wild.
2021-11-03 CVE-2021-30663 high WebKit integer overflow in Apple products allows remote code execution via malicious web content.
2021-11-03 CVE-2021-30665 high Apple's WebKit memory corruption flaw in iOS, macOS, and other OSes allows remote code execution via malicious web content.
2021-11-03 CVE-2020-27932 high Apple's type confusion vulnerability in iOS, iPadOS, macOS, and watchOS allowed malicious apps to execute kernel-level code.
2021-11-03 CVE-2020-27950 high Apple's memory initialization flaw in iOS, iPadOS, macOS, and watchOS allowed malicious apps to leak kernel memory, and it was actively exploited in the wild.
2021-11-03 CVE-2020-27930 high Apple's FontParser memory corruption flaw in iOS, iPadOS, macOS, and watchOS allowed remote code execution when processing malicious fonts.
2021-11-03 CVE-2021-30860 high Apple's CoreGraphics integer overflow vulnerability (CVE-2021-30860) allowed remote code execution via malicious PDFs across iOS, iPadOS, macOS, and watchOS.
2021-11-03 CVE-2020-29583 high Zyxel firewalls and AP controllers shipped with an unchangeable hard-coded credential in an undocumented account.
2021-11-03 CVE-2020-4006 high Command injection flaw in VMware Workspace One products allowed attackers with admin access to execute unrestricted OS commands.
2021-11-03 CVE-2020-3950 high Improper use of setuid binaries in VMware Fusion, VMRC, and Horizon Client for Mac allowed privilege escalation to root.
2022-05-23 CVE-2019-7286 high Apple's iOS, macOS, watchOS, and tvOS suffered a memory corruption vulnerability allowing privilege escalation that was actively exploited in the wild.
2026-03-05 CVE-2017-7921 high Hikvision products had unpatched, exploited improper authentication vulns.
2026-03-05 CVE-2021-30952 high Apple's tvOS, macOS, Safari, iPadOS, and watchOS suffered an integer overflow or wraparound vulnerability, allowing arbitrary code execution via malicious web content.
2026-03-05 CVE-2021-22681 high Rockwell's Studio 5000 Logix Designer exposed key to unauthorized access to Logix controllers.
2026-03-05 CVE-2023-43000 high Apple's macOS, iOS, iPadOS, and Safari versions 16.6 suffer from a Use-After-Free vulnerability exploited in the wild.
2026-02-12 CVE-2026-20700 high Apple iOS, macOS, tvOS, watchOS, and visionOS contain buffer overflow vulnerabilities that could allow arbitrary code execution.
2026-01-27 CVE-2026-24858 high Fortinet's multiple products suffered an authentication bypass allowing unauthorized access via FortiCloud SSO.
2025-12-17 CVE-2025-20393 high Cisco gear with AsyncOS, Web Manager, and Secure Email suffered remote code execution due to improper input validation, allowing root access on affected systems.
2025-12-16 CVE-2025-59718 high Fortinet products allow unauthenticated attackers to bypass authentication via crafted SAML messages
2025-12-15 CVE-2025-43529 high Apple products affected by unpatched use-after-free vulnerability in WebKit.
2025-10-20 CVE-2022-48503 high Apple products with macOS, iOS, tvOS, Safari, and watchOS may allow arbitrary code execution due to an unspecified vulnerability in JavaScriptCore.
2025-10-06 CVE-2010-3765 high Mozilla Firefox, SeaMonkey, and Thunderbird exposed to remote code execution due to unpatched memory corruption issues.
2025-09-04 CVE-2025-53690 high Sitecore's deserialization flaw allowed remote code execution via untrusted data processing
2025-06-16 CVE-2025-43200 high Apple iOS, iPadOS, macOS, watchOS, and visionOS contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
2025-05-14 CVE-2025-32756 high Fortinet products have a stack-based buffer overflow allowing remote code execution without authentication, and are currently being exploited in the wild.
2025-03-13 CVE-2025-24201 high A WebKit out-of-bounds write vulnerability in Apple products allows malicious web content to escape the sandbox, actively exploited in the wild and impacting DIB organizations using Apple devices or WebKit-dependent software.
2023-09-25 CVE-2023-41991 high Apple iOS, iPadOS, macOS, and watchOS improper certificate validation vulnerability
2023-09-25 CVE-2023-41992 high Apple iOS, iPadOS, macOS, and watchOS kernel privilege escalation vulnerability
2023-09-25 CVE-2023-41993 high Apple WebKit vulnerability allows code execution via malicious web content.
2023-06-23 CVE-2023-32434 high An integer overflow vulnerability in Apple's operating systems allows applications to potentially execute code with kernel privileges, and is currently being exploited in the wild.
2023-06-23 CVE-2023-32439 high WebKit Type Confusion Vulnerability in Apple products allows remote code execution.
2023-05-22 CVE-2023-32373 high Apple WebKit Use-After-Free Vulnerability enables code execution.
2023-05-22 CVE-2023-32409 high WebKit sandbox escape vulnerability in Apple products allows remote code execution.
2023-05-22 CVE-2023-28204 high Apple WebKit out-of-bounds read vulnerability
2023-05-12 CVE-2023-25717 high Ruckus Wireless CSRF and RCE vulnerability allows remote code execution.
2023-04-10 CVE-2023-28205 high Apple's Safari and macOS WebKit vulnerable to code execution via malicious web content.
2023-02-14 CVE-2023-23529 high Apple's Safari and iPadOS WebKit vulnerable to code execution via malicious web content
2023-02-02 CVE-2023-22952 high SugarCRM's EmailTemplates RCE flaw exploited in wild
2022-08-18 CVE-2022-22536 high SAP's NetWeaver products exploited for HTTP request smuggling
2022-06-27 CVE-2020-3837 high A memory corruption vulnerability in Apple's operating systems allowed applications to potentially execute code with kernel privileges, and was actively exploited in the wild.
Open questions: What is QXO, Inc.'s founding year? · What is QXO, Inc.'s headquarters location? · What is QXO, Inc.'s company size? · What is QXO, Inc.'s ownership structure? · What is QXO, Inc.'s website URL? · What is QXO, Inc.'s security posture and failure history?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:01:55.442460+00:00