Best Risk-Based Vulnerability Management Software - Page 14

How Many Risk-Based Vulnerability Management Software Products Does G2 Track?

Total Products under this Category: 212

Category Stats (Sep 2026)

  • Average Rating: 4.49/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Ethiack (+0.86%) - Among all products in this category, Ethiack recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Risk-Based Vulnerability Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,300+ Authentic Reviews
  • 212+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Risk-Based Vulnerability Management Software

G2 Grid® for Risk-Based Vulnerability Management Software plotting products by satisfaction and market presence

Highlighted products: Ivanti Neurons for Unified Endpoint Management, Arctic Wolf, Tenable Vulnerability Management, RiskProfiler - External Threat Exposure Management, YesWeHack, Pentera, Check Point Exposure Management, and H1 Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/risk-based-vulnerability-management/grids.json?focus%5B%5D=ivanti-neurons-for-unified-endpoint-management&focus%5B%5D=arctic-wolf&focus%5B%5D=tenable-vulnerability-management&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=yeswehack&focus%5B%5D=pentera&focus%5B%5D=check-point-exposure-management&focus%5B%5D=h1-platform)

Tenacy

Tenacy is the SaaS platform that simplifies cybersecurity management for all IT security teams. Thanks to intelligent modeling of frameworks and risks, Tenacy interconnects all your cyber processes. As a result, you can continuously measure your level of security, effectively monitor your operations, and unite all stakeholders around your cyber vision.

Who Is the Company Behind Tenacy?

  • Seller: Tenacy
  • Year Founded: 2019
  • HQ Location: Lyon, FR
  • Twitter: @Tenacy__
    81 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    50 employees on LinkedIn®

TENET

TENET is a risk intelligence platform purpose-built for the Microsoft ecosystem to deliver unified visibility and proactive risk assessment across Azure and M365. It serves as a single source of truth for identifying, prioritizing, and mitigating cloud risk at scale—enabling organizations to shift from reactive firefighting to continuous, intelligence-driven security operations. Key Features: - Attack surface management: Identify risky entry points, misconfigurations, and third-party exposures. Visualize attack paths, map findings to MITRE ATT&CK, prioritize remediation, and manage incidents from a unified cloud risk view. - Anomaly detection: Detect issues early with real-time analysis of cloud workloads, identities, and applications, helping teams identify abnormal behaviour and mitigate risks before they become incidents. - Compliance readiness: Simplify audits with continuous compliance monitoring, guided remediation, and risk-prioritized insights. Reduce costs and manual effort while shrinking audit preparation from weeks to hours. - Microsoft 365: Gain visibility into external sharing, device risk, license utilization, and Copilot agents. Understand how identities, configurations, and data exposures combine to create risk across your cloud environment. - Access governance: Monitor human and non-human identities, analyze effective permissions across Entra ID and RBAC, and maintain clear visibility into who can access resources across your cloud estate. - AI monitoring: Discover and inventory AI models, agents, and cognitive services. Continuously monitor performance, reliability, and security posture while identifying AI-specific risks and prioritizing remediation. - Intelligent insights: Investigate and resolve issues faster with BriteAI. Transform live data into actionable insights, identify root causes through natural language queries, and receive precise remediation guidance. Core Value: TENET eliminates blind spots and reduces mean time to remediation (MTTR) through end-to-end Microsoft cloud visibility and guided remediation. It lowers compliance and audit overhead, enables teams to proactively identify and mitigate risks before they escalate, and scales security operations efficiently with AI-powered insights and autonomous remediation with full context via the TENET MCP server. For more information, visit www.aesonsolutions.com.

Who Is the Company Behind TENET?

The Nanitor Continuous Threat Exposure Management (CTEM) Platform

Nanitor Continuous Threat Exposure Management (CTEM) Platform is an enterprise-grade cybersecurity solution built to help organizations continuously monitor, assess, and reduce their real security exposures - not just known vulnerabilities - across all IT assets. Rather than relying on periodic scans or patch-cycles, Nanitor implements a continuous, asset-centric, and risk-based approach to threat exposure. At its core, Nanitor’s CTEM platform transforms security from reactive patch-management into proactive, business-aligned risk management - giving leadership transparency over what matters most and security teams clarity on what to fix next.

Who Is the Company Behind The Nanitor Continuous Threat Exposure Management (CTEM) Platform?

  • Seller: Nanitor
  • Year Founded: 2014
  • HQ Location: Reykjavík, IS
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Thrivaca

Utilize real-world insights into the impacts and dynamics driving digital risk. Know where, why, and how much digital risk is impacting the organization with Thrivaca. Efficiently direct cyber investment and effort to the largest sources of risk and address the areas of most significant impact. Demonstrate the relationship between cyber budget and mitigated risk through our T-Score and Cyber Efficiency Index. The Thrivaca platform provides comprehensive data and advanced quantitative processes: • Threat trend-tracking on your industry derived from over 9 million attacks per day • A machine learning algorithm that simulates actual threat actor patterns • Industry-specific risk-probability patterns derived from multi-year history • Top Gartner-rated vulnerability scanning technology • Delivered via a SOC 1 / SOC 2 cloud platform • Insurance-grade quantitative models that utilize actuarially-based risk valuations • Thrivaca M&A provides pre-and post-merger analyses, identifying specific mitigation strategies, solutions, and cost-of-risk effects • Thrivaca CI provides the Cyber Insurance industry – underwriters and brokers – with rapid turnaround of any actuarially-driven risk valuation solution, with minimally invasive data collection • Thrivaca Cloud brings a complete ongoing analysis of all cloud environments individually and collectively including cloud migration and integration risk exposure at its sources • Fully auditable and traceable results, based on “Zero-Trust” principles throughout Arx Nimbus Thrivaca measures controls across the entire enterprise in alignment with regulator-mandated standards, including FFIEC, NIST 800-53, FERC, SANS, HIPAA, and ISO. Knowing the financial trade-offs of options and strategies allows companies to prioritize and invest with confidence and precision. Our accelerated delivery cycle allows for the rapid reprioritization of cyber solutions and actionable next steps.

Who Is the Company Behind Thrivaca?

Uncloak

Who Is the Company Behind Uncloak?

  • Seller: Uncloak
  • Year Founded: 2016
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    4 employees on LinkedIn®

Vornin

Vornin combines vulnerability scanning, risk-based prioritisation, remediation tracking and compliance evidence in one verifiable workflow. Scan web apps, APIs, infrastructure, containers, cloud and code. Detect vulnerabilities across your attack surface with defined scan checks behind every finding. Resolve issues with deduplicated findings prioritised using CVSS, EPSS and CISA KEV, so the same inputs give the same priority. AI adds context, remediation guidance and triage support; it does not create findings. Assign ownership, track SLAs, verify fixes with rescans, and connect workflows to Jira, GitHub and more. Prove your compliance with every finding mapped to controls across 9 frameworks, including NIS2, DORA, ISO 27001, SOC 2, PCI DSS and HIPAA. Every status change is written to a tamper-evident chain, with auditor-ready evidence available for export. EU-hosted with EU data residency. Built for lean IT and security teams managing security and compliance as one workstream.

Who Is the Company Behind Vornin?

  • Seller: Vornin
  • Year Founded: 2026
  • HQ Location: Copenhagen, DK
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

vRx

Who Is the Company Behind vRx?

  • Seller: Vicarius
  • Year Founded: 2016
  • HQ Location: New York, New York
  • Twitter: @vicariusltd
    2,018 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    100 employees on LinkedIn®

Vulnara

Vulnara is an AI-powered vulnerability management and application security platform designed to help development and security teams identify, understand, prioritize, and remediate security issues faster. The platform combines security scanning with detailed technical context and AI-assisted remediation, helping teams move from vulnerability discovery to actionable fixes within their existing development workflows. Vulnara can generate remediation guidance, create fixes through pull requests, integrate with CI/CD pipelines and development tools, and continuously monitor projects for security risks. Unlike traditional per-developer security pricing, Vulnara uses a straightforward usage-based model, allowing teams to scale security testing without increasing costs simply because their engineering team grows. Vulnara is built around a simple objective: turn security findings into understandable, actionable fixes with less manual effort.

Who Is the Company Behind Vulnara?

Vulnerability and Compliance Scan

SecureVia simplifies securing and hardening business applications by giving you a prioritized list of vulnerabilities to be remediated. You don't need to be a security expert as we do the research and apply the best security standards automatically.

Who Is the Company Behind Vulnerability and Compliance Scan?

  • Seller: SecureVia
  • Year Founded: 2020
  • HQ Location: Acton, US
  • Twitter: @securevia
    17 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Wabbi

Delivering Scalable Application Security for Enterprise Development teams.

Who Is the Company Behind Wabbi?

  • Seller: Wabbi
  • Year Founded: 2018
  • HQ Location: Boston, US
  • LinkedIn® Page: linkedin.com
    15 employees on LinkedIn®

we45

AppSec Testing(AST) - Whatever your motivation, a proactive security push or a compliance compulsion, our AST service can help keep your application secure against external threats. Security Automation - Secure your agile Software Development Life Cycle(SDLC) without compromising on quality or time. AppSec Training - Our numerous/variegated training offerings help product teams gain the security understanding necessary to keep their deployments secure. Orchestron - Make Application Security efficient with one of the most integral parts of a modern DevSecOps toolchain - An AVC engine. Threat PlayBook - A (relatively) Unopinionated framework that faciliates Threat Modeling as Code married with Application Security Automation on a single Fabric. Perform Iterative Threat Modeling in an Agile Environment with Threat Playbook.

Who Is the Company Behind we45?

  • Seller: we45
  • Year Founded: 2019
  • HQ Location: San Jose, US
  • LinkedIn® Page: www.linkedin.com
    37 employees on LinkedIn®

XRATOR

XRATOR is a comprehensive cybersecurity platform designed to empower organizations, particularly small and medium-sized businesses (SMBs, to proactively manage and mitigate cyber risks. By integrating continuous threat exposure management with strategic risk assessment, XRATOR enables businesses to identify vulnerabilities, prioritize them based on actual business impact, and implement effective remediation strategies. This approach not only enhances security posture but also aligns cybersecurity efforts with organizational objectives, facilitating resilient business growth. Key Features and Functionality: - Complete Visibility: XRATOR provides thorough asset discovery across all environments, including cloud and on-premises, ensuring no asset—be it shadow IT or forgotten infrastructure—is overlooked. - Smart Prioritization: The platform prioritizes vulnerabilities by assessing their real-world business impact and threat context, allowing organizations to focus on the most critical 3% of vulnerabilities that could significantly affect operations. - Integrated Compliance: Compliance is seamlessly embedded into the scanning and reporting processes, eliminating the need for separate compliance tools and enabling continuous monitoring without added complexity. - Right-Sized Solution: XRATOR offers enterprise-level capabilities without the complexity or cost associated with large-scale risk management systems, making it an ideal solution for SMBs seeking comprehensive yet straightforward cybersecurity management. - Intelligent Vulnerability Management: The platform continuously maps infrastructure and identifies weaknesses across both cloud and on-premises environments. - Collaborative Management: XRATOR provides a unified platform for security teams, facilitating cross-functional workflow integration and enhancing collaboration. - Automated Compliance: It streamlines regulatory compliance processes by aligning with industry standards, reducing the burden of manual compliance efforts. - Business Risk Quantification: The platform automatically quantifies vulnerabilities, assigning risk scores based on business impact to aid in smarter prioritization. - Cyber Attack Surface Management: XRATOR offers complete visibility and control over digital assets, enabling proactive vulnerability management. - Threat Intelligence Integration: Real-time threat intelligence feeds provide updates on emerging threats and vulnerabilities, keeping organizations informed and prepared. Primary Value and Problem Solved: XRATOR addresses the critical challenge of managing cyber risks in a rapidly evolving threat landscape. By providing a platform that combines risk-based vulnerability management with cyber risk quantification and attack surface management, XRATOR enables organizations to: - Proactively Identify and Mitigate Threats: Organizations can discover and address vulnerabilities before they are exploited, reducing the likelihood of cyber incidents. - Align Cybersecurity with Business Objectives: By quantifying risks based on business impact, XRATOR ensures that cybersecurity efforts are in sync with organizational goals, optimizing resource allocation. - Simplify Compliance and Reporting: The platform automates compliance monitoring and reporting, easing the burden of regulatory requirements and facilitating clear communication with stakeholders. - Enhance Operational Efficiency: By focusing on the most impactful vulnerabilities and integrating with existing security tools, XRATOR streamlines cybersecurity operations, allowing teams to work more effectively. In essence, XRATOR empowers organizations to build inherent resistance to cyber threats, transforming cybersecurity from a reactive necessity into a strategic asset that supports and accelerates business growth.

Who Is the Company Behind XRATOR?

  • Seller: XRATOR
  • Year Founded: 2021
  • HQ Location: Nantes, FR
  • LinkedIn® Page: www.linkedin.com
    19 employees on LinkedIn®

Zeguro

Zeguro offers cyber insurance and an easy-to-use cyber risk management solution, Zeguro Cyber Safety. Designed for small to midsize businesses, our Cyber Safety platform includes: cybersecurity training to improve employee security awareness, customizable pre-built security policy templates for regulatory compliance, and automated web app scanning to monitor for and mitigate vulnerabilities. Zeguro Cyber Safety users can also enjoy potential savings in their cyber insurance, which Zeguro prices based on your organization's risk profile. Zeguro's cyber insurance is back by HSB/MunichRe's global 24/7 claims team with over 20 years in cyber insurance claims experience. Our insurance is A++ rated (A.M. Best). Together, Zeguro's cyber insurance and Cyber Safety solutions protect your business from insider and outsider threats and provide a safety net in the event of a data breach.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate Zeguro?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)

Who Is the Company Behind Zeguro?

  • Seller: Zeguro
  • Year Founded: 2016
  • HQ Location: San Francisco, US
  • Twitter: @Zeguroinc
    199 Twitter followers
  • LinkedIn® Page: linkedin.com
    4 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About Zeguro?

AI-generated summary from verified user reviews

Pros
  • Users praise the ease of use of Zeguro, finding its interface intuitive and delightful to operate.
  • Users love the great user-friendly interface of Zeguro, finding it easy and enjoyable to operate.
Cons
  • Users find the limited deployment options with Zeguro restrictive, affecting integration with other platforms.

What Are Recent G2 Reviews of Zeguro?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024