Best Risk-Based Vulnerability Management Software - Page 7

How Many Risk-Based Vulnerability Management Software Products Does G2 Track?

Total Products under this Category: 194

Category Stats (Aug 2026)

  • Average Rating: 4.48/5 (↓0.02 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Ivanti Neurons for RBVM (+2.94%) - Among all products in this category, Ivanti Neurons for RBVM recorded the largest rating increase compared to last month

Last updated: August 07, 2026

How Does G2 Rank Risk-Based Vulnerability Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 4,800+ Authentic Reviews
  • 194+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Risk-Based Vulnerability Management Software

G2 Grid® for Risk-Based Vulnerability Management Software plotting products by satisfaction and market presence

Highlighted products: Arctic Wolf, Tenable Vulnerability Management, Recorded Future, RiskProfiler - External Threat Exposure Management, YesWeHack, H1 Platform, Check Point Exposure Management, and Pentera.

Underlying data: [Grid® JSON](https://www.g2.com/categories/risk-based-vulnerability-management/grids.json?focus%5B%5D=arctic-wolf&focus%5B%5D=tenable-vulnerability-management&focus%5B%5D=recorded-future&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=yeswehack&focus%5B%5D=h1-platform&focus%5B%5D=check-point-exposure-management&focus%5B%5D=pentera)

Sponsored

Upwind

Upwind is the runtime-first cloud security platform that secures your deployments, configurations, and applications by providing real-time visibility from the inside out. We’ve built a unified fabric that maps your environment as it runs - revealing what’s truly at risk, what’s actively happening, and how to respond quickly and effectively. With Upwind, security, dev, and ops teams move faster, stay focused, and fix risks that matter most.

Visit website

Tripwire IP360

A Key Part of Fortra (the new face of HelpSystems) Tripwire is proud to be part of Fortra’s comprehensive cybersecurity portfolio. Fortra simplifies today’s complex cybersecurity landscape by bringing complementary products together to solve problems in innovative ways. These integrated, scalable solutions address the fast-changing challenges you face in safeguarding your organization. With the help of the powerful protection from Tripwire IP360 and others, Fortra is your relentless ally, here for you every step of the way throughout your cybersecurity journey.

Average Rating: 3.3/5.0

Total Reviews: 2

How Do G2 Users Rate Tripwire IP360?

  • Has the product been a good partner in doing business?: 6.7/10 (Category avg: 9.2/10)

Who Is the Company Behind Tripwire IP360?

  • Seller: Fortra
  • Year Founded: 1982
  • HQ Location: Eden Prairie, Minnesota
  • Twitter: @fortraofficial
    2,773 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,755 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Tripwire IP360?

What Are G2 Users Discussing About Tripwire IP360?

TrueSight Vulnerability Management for Third-Party Applications

TrueSight Vulnerability Management helps security and IT operations teams prioritize and remediate risks based on potential impact to the business.

Average Rating: 3.8/5.0

Total Reviews: 2

Who Is the Company Behind TrueSight Vulnerability Management for Third-Party Applications?

Who Uses This Product?

  • Company Size: 67% Small, 33% Medium

What Are Recent G2 Reviews of TrueSight Vulnerability Management for Third-Party Applications?

What Are G2 Users Discussing About TrueSight Vulnerability Management for Third-Party Applications?

Visore Security Management Platform

Visore simplifies your organizations security operations with a Single pane-of-glass SecOps Platform that solves interoperability, built to address the #1 challenge plaguing IT and Cyber teams: comprehensive & up-to-date asset inventory. Asset inventory, consolidated data and threat intelligence, all in one place enable valuable insights with just one click.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate Visore Security Management Platform?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Visore Security Management Platform?

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Visore Security Management Platform?

What Are G2 Users Discussing About Visore Security Management Platform?

AttackTree

AttackTree is a vulnerability management software that helps predict hacking attacks and develop prevention schemes.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate AttackTree?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind AttackTree?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of AttackTree?

Black Kite

In today’s threat landscape, understanding your cyber risk exposure - across vendors, systems, and the extended supply chain - is critical. At Black Kite, our mission is to equip business and security leaders with a complete and accurate view of their cyber ecosystem risk extending out to their 4th-, 5th-, and Nth-parties. The Black Kite platform: - Unlocks continuous risk intelligence, including Black Kite’s Ransomware Susceptibility Index® (RSI), Adversary Susceptibility Index (ASI), and Data Breach Index (DBI) - Quantifies Financial Impact of risk using Open FAIR™ - Detects cyber exposure and high-risk signals across your supplier ecosystem and out to your Nth party with Black Kite FocusTags™ - Uses AI to automate vendor assessments, questionnaires, and gap analysis Our offerings: Black Kite Monitor: Continuous, real-time visibility into the cyber health of your third-party ecosystem - helping you build resilience across your supply chain. By providing accurate, always-up-to-date risk intelligence on vendors, Black Kite Monitor empowers teams to make informed risk decisions. Black Kite Assess: Delivers AI-powered cyber assessments built on trusted risk intelligence - including technical findings, posture ratings, and real-time risk signals. Black Kite Assess empowers teams to automate everything from document review and gap analysis to assessing vendor controls against custom questionnaires and standard frameworks and regulations, such as NIST and GDPR, while recommending remediations to engage third-parties on. Black Kite Extend: Gives organizations deeper visibility into the interconnected risks beyond their direct third parties. Built for teams managing complex supply chains or software vendor ecosystems, Black Kite Extend surfaces risk insights across fourth-, fifth-, and Nth-party relationships - helping you uncover hidden exposures and improve risk posture across your extended ecosystem. Whether it’s identifying critical dependencies, geopolitical risk, or sanctioned entities, Extend equips you with the context needed to make smarter decisions at scale.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Black Kite?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Black Kite?

  • Seller: Black Kite
  • Year Founded: 2016
  • HQ Location: Boston, Massachusetts
  • Twitter: @BlackKiteTech
    1,502 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    127 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Do G2 Reviewers Say About Black Kite?

AI-generated summary from verified user reviews

Pros
  • Users find Black Kite extremely easy to use, appreciating quick onboarding and valuable engagement throughout the process.
  • Users appreciate the easy implementation of Black Kite, allowing quick onboarding and immediate value from the tool.
  • Users commend Black Kite for their innovative engagement and flexibility in vendor risk monitoring, enhancing user experience.
  • Users find implementation incredibly easy with Black Kite, enabling them to gain value quickly from the start.
  • Users value the innovative features and proactive engagement of Black Kite, enhancing their overall experience.

What Are Recent G2 Reviews of Black Kite?

Centraleyes

Centraleyes is a next generation GRC platform that gives organizations an unparalleled understanding of their cyber risk and compliance. Centraleyes provides an exceptional ability to see, understand and react to growing risks and gaps, in a place where other solutions are ineffective. Centraleyes’s customers have automated and orchestrated their GRC function, to the point where it is 10x faster and 10x better. This is truly cyber risk management reimagined.

Average Rating: 4.3/5.0

Total Reviews: 3

Who Is the Company Behind Centraleyes?

Who Uses This Product?

  • Company Size: 67% Large, 33% Medium

What Do G2 Reviewers Say About Centraleyes?

AI-generated summary from verified user reviews

Pros
  • Users find Centraleyes essential for insightful compliance management, helping identify cyber threats and compliance strengths and weaknesses.
  • Users find compliance simplification valuable in identifying cyber threats and managing compliance effectively with Centraleyes.
  • Users find Centraleyes offers valuable insights into cyber threats, enhancing GRC management and compliance understanding.
  • Users find that Centraleyes provides valuable insights into cyber threats and compliance management, enhancing their GRC strategies.
  • Users find Centraleyes provides valuable insights into cyber threats and compliance strengths, enhancing GRC management effectively.
Cons
  • Users find it challenging to generate reports due to filtering issues that fail to meet diverse stakeholder needs.
  • Users find inadequate reporting in Centraleyes limits their ability to satisfy all stakeholders' needs effectively.
  • Users experience lack of clarity in Centraleyes' reports, which may not meet all stakeholders' needs effectively.
  • Users find limited reporting capabilities in Centraleyes, making it challenging to meet all stakeholders' needs effectively.
  • Users find it challenging due to poor reporting in Centraleyes, limiting the ability to meet stakeholder needs effectively.

What Are Recent G2 Reviews of Centraleyes?

CybelAngel

CybelAngel protects its customers with External Attack Surface Management (EASM) solutions that are powered by the most comprehensive external asset discovery and threat detection technologies available. Built upon close to a decade of machine learning, our advanced platform scans the entirety of the internet every 24 hours to uncover unknown assets and shadow IT, cloud services, connected devices, fraudulent domains and exposed credentials — the sources attackers use to access confidential data, launch phishing campaigns or initiate destructive ransomware attacks. CybelAngel's combination of machine learning and expert human analysis provides deep visibility into the most critical threats, long before they’re exploited.

Average Rating: 4.7/5.0

Total Reviews: 6

How Do G2 Users Rate CybelAngel?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind CybelAngel?

  • Seller: CybelAngel
  • Year Founded: 2013
  • HQ Location: Paris, Île-de-France, France
  • Twitter: @CybelAngel
    3,408 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    163 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 83% Large, 17% Medium

What Are Recent G2 Reviews of CybelAngel?

Cyberwatch

Cyberwatch is a server vulnerability monitoring solution with integrated patch management functionality.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Cyberwatch?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Cyberwatch?

Who Uses This Product?

  • Company Size: 100% Large

What Do G2 Reviewers Say About Cyberwatch?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the automation features of Cyberwatch, enabling proactive security management and efficient vulnerability handling.
  • Users commend the highly responsive customer support of Cyberwatch, significantly enhancing their overall experience.
  • Users find Cyberwatch's platform to be incredibly intuitive, simplifying vulnerability management and enhancing user experience.
  • Users value the ease of use of Cyberwatch, appreciating its intuitive interface and quick onboarding process.
  • Users appreciate the quick onboarding process of Cyberwatch, making it easy for all experience levels to get started.

What Are Recent G2 Reviews of Cyberwatch?

Echelon

Echelon — your cybersecurity check-up solution. Just like a health check-up prevents illness, our AI-driven solution for ongoing cybersecurity audits prevents cyber threats — before they lead to financial loss or data breaches. Just 5 reasons to choose Echelon: 1. Fix Faster with AI. Our AI tool provides step-by-step guidance to remediate every detected vulnerability. Less routine for your team—more profit for you. 2. Machine Learning Leak Processing. Machine Learning enables Echelon to efficiently process leaked data, ensuring none of your sensitive information is exposed publicly. 3. Quick & Easy Setup. Just enter and confirm your domain or IP. No downloads. No access permissions needed. 4. Automatic Threat Detection. Finds security gaps before attackers do. 5. Echelon Never Sleeps. Audits are performed regularly. 24/7 CVE monitoring — if a new threat emerges, you'll be notified immediately. 3 simple steps to start: - Visit Echelon’s Website and Sign Up - Enter Domain/IP and Choose a Plan - Stay one step ahead of cyber threats – Echelon ensures 24/7 security

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Echelon?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Echelon?

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About Echelon?

AI-generated summary from verified user reviews

Pros
  • Users value the enhanced cybersecurity measures of Echelon, providing an additional layer of protection against risks.
  • Users value Echelon for its enhanced risk management, providing an important additional layer of protection and reassurance.
  • Users value the multi-layered security of Echelon, enhancing protection and minimizing risks effectively.
Cons
  • Users find the technical language complex, making it challenging for those less familiar with the product.
  • Users find the technical language complex, potentially challenging for those less familiar with the concepts.

What Are Recent G2 Reviews of Echelon?

Faraday Platform

Faraday ingests thousands of vulnerabilities from various assets and visualizes findings in a clear, dynamic, and intuitive dashboard. It is a comprehensive vulnerability management tool that helps security teams prioritize critical vulnerabilities, focusing on those that are exploitable to reduce noise and streamline reporting. Faraday can be deployed both in the cloud and on-premises, available in professional, corporate, and open-source versions. The company strongly supports open-source software (OSS) as they began as a small group of pentesters who needed to manage vulnerabilities and generate reports, leading them to develop this tool. Now, Faraday is accessible on GitHub for any pentester needing to create penetration testing reports. Among its many features, Faraday supports over 160 tools to consolidate work in one place. It also integrates seamlessly with Jira, ServiceNow, SolarWinds, and GitLab. The platform includes its own vulnerability scoring system to prioritize vulnerabilities as a hacker would, identifying exploitable vulnerabilities over seemingly critical ones that pose no real risk. Faraday is designed to meet the needs of small to large companies, allowing them to scale their security operations efficiently.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Faraday Platform?

  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Faraday Platform?

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Faraday Platform?

Fluid Attacks

Implement Fluid Attacks' comprehensive, AI-powered solution into your SDLC and develop secure software without delays. As an all-in-one solution, Fluid Attacks accurately finds and helps you remediate vulnerabilities throughout the SDLC and ensures secure software development. The solution integrates its AI, automated tool, and team of pentesters to perform SAST, SCA, DAST, CSPM, SCR, PtaaS and RE to help you improve your security posture. This way, Fluid Attacks delivers accurate knowledge of the security status of your application. This means security goes alongside innovation without hindering your speed. Fluid Attacks provides you with expert knowledge about vulnerabilities and support options that enable you to remediate the security issues in your application.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate Fluid Attacks?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)

Who Is the Company Behind Fluid Attacks?

  • Seller: Fluid Attacks
  • Year Founded: 2001
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    136 employees on LinkedIn®
  • Phone: +14154042154

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Fluid Attacks?

Hackuity.io

Hackuity is the comprehensive security solution that orchestrates and automates the vulnerability management process. Hackuity’s platform aggregates and normalizes all your security assessment practices, whether automated or handmade, and enriches them so security practitioners can, at last, create risk-driven remediation plans and align their priorities with their current and future exposure to threats. Fully customizable, the platform fits the client technical context and security requirements either in a full-Saas mode, On-premise or Hybrid installation mode. Hackuity proposes the right offer regarding the company's experience in vulnerability management and field of activity : - Risk-based vulnerability management - Continuous Monitoring - Augmented pentest - Hackuity for MSSP The company was founded in 2018 and is based in Lyon, France.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Hackuity.io?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Hackuity.io?

What Are G2 Users Discussing About Hackuity.io?

ManageEngine Vulnerability Manager Plus

With Vulnerability Manager Plus, right from detection, and assessment of vulnerabilities to eliminating them with an automated patching workflow, all aspects of vulnerability management are made easy with a centralized console.

Average Rating: 4.7/5.0

Total Reviews: 3

How Do G2 Users Rate ManageEngine Vulnerability Manager Plus?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)

Who Is the Company Behind ManageEngine Vulnerability Manager Plus?

  • Seller: Zoho
  • Year Founded: 1996
  • HQ Location: Austin, TX
  • Twitter: @Zoho
    137,880 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    30,766 employees on LinkedIn®
  • Phone: +1 (888) 900-9646

Who Uses This Product?

  • Company Size: 67% Medium, 33% Large

What Do G2 Reviewers Say About ManageEngine Vulnerability Manager Plus?

AI-generated summary from verified user reviews

Pros
  • Users praise the effective detection capabilities of ManageEngine Vulnerability Manager Plus for global patch management simplicity.
  • Users find the ease of use in ManageEngine Vulnerability Manager Plus makes global patch management simple and efficient.
  • Users find that ManageEngine Vulnerability Manager Plus is the best tool for simple and effective patch management globally.
  • Users value the ease of managing patches globally with ManageEngine Vulnerability Manager Plus for efficient patch management.
  • Users find ManageEngine Vulnerability Manager Plus an easy-to-manage patch management tool for global machine updates.
Cons
  • Users report issues with false positives, as some CVE IDs marked vulnerable do not align with ManageEngine assessments.
  • Users report inaccuracy issues with ManageEngine Vulnerability Manager Plus, as some CVE IDs are missed in reports.
  • Users report security vulnerabilities as discrepancies in CVE identification, hindering effective threat management in ManageEngine.
  • Users report discrepancies with CVE identification, as some vulnerabilities in MDE reports are missed by ManageEngine.

What Are Recent G2 Reviews of ManageEngine Vulnerability Manager Plus?

NopSec Unified VRM

NopSec Unified Vulnerability Risk Management (VRM) correlates vulnerability data with your IT environment and attack patterns in the wild to help you avoid false positives and find the threats that matter. Unified VRM prioritizes security vulnerabilities based on business risk and context with proprietary threat prediction models and cyber intelligence – including malware, exploit, patching and social media feeds to predict the true probability of attacks. It replaces manual remediation tasks with automated workflow, integrated communication capabilities and incident management – guided by rich visualization dashboards for easy reporting on current status.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate NopSec Unified VRM?

  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind NopSec Unified VRM?

  • Seller: NopSec
  • Year Founded: 2013
  • HQ Location: New York, US
  • Twitter: @nopsec
    2,200 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    47 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of NopSec Unified VRM?

What Are G2 Users Discussing About NopSec Unified VRM?

Ostrich Birdseye

Ostrich Cyber-Risk helps organizations reduce the complexity of identifying, quantifying and communicating cyber and operational risks related to their cybersecurity posture with its Birdseye™ SaaS solution. Benchmarked against NIST CSF with references to best standards, like NIST 800-53, ISO 27001, CIS 18, etc. Birdseye is a unified qualitative and quantitative cyber risk management application that offers an intuitive assessment workflow to track your organization’s risk over time, all in one place. The Birdseye™ proprietary features include continuous progress tracking, real world data insights from Advisen for peer comparison, CRQ Simulator that simulates unlimited risk scenarios to enable risk-reduction ROI calculations, and shareable reports. Learn more at https://www.ostrichcyber-risk.com/.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate Ostrich Birdseye?

  • Reporting: 10.0/10 (Category avg: 8.8/10)
  • Risk-Prioritization: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Ostrich Birdseye?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Ostrich Birdseye?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024