Top Free Vulnerability Scanner Software - Page 6

How Many Vulnerability Scanner Software Products Does G2 Track?

Total Products under this Category: 235

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Armis (+0.18%) - Among all products in this category, Armis recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Vulnerability Scanner Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 7,900+ Authentic Reviews
  • 235+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Vulnerability Scanner Software

G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, CrowdStrike Falcon Cloud Security, Tenable Nessus, Orca Security, Astra Pentest, Intruder, and Burp Suite.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=tenable-nessus&focus%5B%5D=orca-security&focus%5B%5D=astra-pentest&focus%5B%5D=intruder&focus%5B%5D=burp-suite)

Luna

Luna is an external vulnerability scanning platform that helps businesses discover and fix security weaknesses across their internet-facing infrastructure. Using 11,000+ security templates, Luna detects CVEs, misconfigurations, and common web vulnerabilities including XSS, SQLi, RCE, and SSRF across websites, servers, and network services. The platform offers four scan modes, Quick, Comprehensive, CVE-only, and Deep, with port scanning across the top 1,000 ports, SSL/TLS certificate analysis, and CVSS-based risk scoring for every finding. Vulnerabilities are mapped to OWASP Top 10 2025 categories with compliance reporting for Cyber Essentials, ISO 27001, SOC 2, PCI DSS, and GDPR. Luna is fully cloud-based with nothing to install. Teams can add domains or IP addresses and run their first scan in under five minutes. Scheduled scans run on custom cron expressions with Slack and email alerts for critical findings. A full REST API supports CI/CD pipeline integration. The platform includes vulnerability lifecycle management to track findings from Open to Acknowledged to Fixed, with false positive marking and remediation guidance. Reports export as PDF, CSV, or JSON. Luna is designed for lean IT teams, startups, and SMEs that need enterprise-grade vulnerability scanning without enterprise pricing or complexity. Plans start at $249/month for up to 50 targets, with a 14-day free trial.

Who Is the Company Behind Luna?

  • Seller: Luna
  • Year Founded: 2025
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

NESS

NESS (Network Environment Scanning and Security), focuses on developing software to help companies prevent and predict cyberattacks and failures within their technological infrastructure.

Who Is the Company Behind NESS?

  • Seller: NESS
  • Year Founded: 2023
  • HQ Location: Bogotá, CO
  • LinkedIn® Page: www.linkedin.com
    6,042 employees on LinkedIn®

N-Stalker

N-Stalker Web Application Security Scanner X is a web security assessment solution for web applications.

Who Is the Company Behind N-Stalker?

  • Seller: N-Stalker
  • Year Founded: 2000
  • HQ Location: Curitiba, BR
  • Twitter: @nstalker
    677 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4 employees on LinkedIn®

Olimpio Security

Olimpio is an external vulnerability scanner built for UK small businesses. It scans your domain for security weaknesses — open ports, missing email authentication records, expired SSL certificates, HTTP security headers, exposed API keys, and known software vulnerabilities — and explains every finding in plain English with clear remediation steps. Most vulnerability scanners are built for enterprise security teams with technical staff to interpret the results. Olimpio is different. Results are explained in plain English so business owners and non-technical managers can understand exactly what is wrong and how to fix it. Key features: external port scanning (standard and deep mode), DNS and email security checks (DMARC, SPF, DKIM), SSL certificate monitoring, HTTP security header analysis, GitHub secrets scanning for exposed API keys, Cyber Essentials control mapping (CE1–CE5), AI-generated plain-English finding explanations, PDF security reports, and security score tracking over time. Free tier available. Starter plan from £49/month.

Who Is the Company Behind Olimpio Security?

Oversecured

Enterprise vulnerability scanner for Android and iOS apps. It offers app owners and developers the ability to secure each new version of a mobile app by integrating Oversecured into the development process.

Who Is the Company Behind Oversecured?

ScanLabsAI - Advanced Vulnerability Scanner

ScanLabsAI is an AI-powered website vulnerability scanner built for agencies, MSPs and development teams responsible for security across many client sites. It scans against the OWASP Top 10 for Web, API and LLM applications — the last of which most vulnerability scanners do not cover at all. Alongside conventional web security checks, ScanLabsAI detects leaked AI and LLM provider API keys, exposed agentic-tool configuration and GraphQL introspection left enabled: the failure modes that appear most often in sites built quickly with AI coding tools. Each deep scan runs more than 40,000 vulnerability checks, covering CVE detection, SSL/TLS analysis, security header configuration, DNS settings and common web application weaknesses. Connected GitHub repositories are scanned as well as the live site, surfacing hardcoded secrets and vulnerable dependencies that never appear in a black-box scan. Findings come with AI-written remediation guidance explaining what to change and why. Scanning is non-intrusive and read-only, so it never modifies or disrupts the target site. Deep scans complete in under twenty minutes, run in the background with notifications, and can be exported as PDF reports. Vulnerability reports are never stored. For agencies and MSPs, the Agency plan covers up to 50 client websites for £249 per month — under £5 per site — with white-label PDF reports delivered under your own brand, team access with role-based permissions, and no long-term contract. A 14-day free trial is available without a credit card. Individual users can scan without a subscription: the first scan of every website is free, and further scans run on AI credit packs starting at £9.99. ScanLabsAI also provides a native Model Context Protocol (MCP) server, published in the official MCP Registry, so scans can be run directly from Claude and other MCP-compatible AI assistants — either through the hosted endpoint or the @scanlabsai/mcp-server npm package.

Who Is the Company Behind ScanLabsAI - Advanced Vulnerability Scanner?

Vuln0x

Vuln0x is developed by Solustiq Yazılım ve Yapay Zeka Teknolojileri A.Ş., an AI-driven software company headquartered in Edirne, Turkey, with international operations through Tech In Wise IT Solutions L.L.C. in Dubai. Solustiq specializes in building AI-powered SaaS products across security, market research, and developer tooling. Vuln0x is the company's dedicated security platform, built from the ground up to make professional-grade penetration testing accessible to teams of any size. Vuln0x combines automated vulnerability scanning with Sentinel, an autonomous AI penetration testing agent that orchestrates 29+ Kali Linux security tools through a chat interface. Sentinel follows a 7-phase attack methodology covering reconnaissance, surface analysis, CMS detection, parameter discovery, injection testing, authentication testing, and report generation. It scans using 5,800+ Nuclei templates, adapts to WAF detection, chains findings into deeper analysis, and delivers structured reports with severity ratings and remediation steps. Additional capabilities include scheduled scans for continuous monitoring, a risk scoring dashboard, API and CI/CD integration, and professional PDF reporting all with zero setup required. Vuln0x solves a critical gap for SMBs, digital agencies, and DevSecOps teams: getting pentest-grade security results without the pentest-grade cost and complexity. Traditional penetration testing requires expensive consultants and days of manual work. Automated scanners catch surface-level issues but miss chained vulnerabilities. Vuln0x bridges both Sentinel thinks like a pentester, acts autonomously, and reports like a professional, so teams can ship secure applications without slowing down development or breaking the budget.

Who Is the Company Behind Vuln0x?

Vulseek by Securetia

Vulseek is a modern Vulnerability Management as a Service (VMaaS) solution that simplifies how organizations identify, assess, and remediate security vulnerabilities across their infrastructure. Designed with usability and effectiveness in mind, Vulseek automates the entire vulnerability lifecycle, from detection to resolution, empowering teams to stay secure without added complexity. At its core, Vulseek combines automated asset discovery and scanning with intelligent risk prioritization, allowing security teams to focus on what truly matters. Its customizable dashboards, real-time alerts, and integrations with popular ticketing systems and SIEMs help ensure vulnerabilities are addressed swiftly and systematically. Built by cybersecurity experts, Vulseek is trusted by companies across industries to: Maintain continuous visibility into their attack surface Reduce mean time to remediation (MTTR) Meet compliance requirements with ease Whether you're a small business or a growing enterprise, Vulseek provides reliable, accessible, and actionable vulnerability management without the overhead of traditional tools.

Who Is the Company Behind Vulseek by Securetia?

WithSecure Elements Exposure Management

WithSecure™ Elements Exposure Management (XM) is a continuous and proactive solution that predicts and prevents breaches against your company’s assets and business operations. Elements XM provides visibility into your attack surface and enables the efficient remediation of its highest-impact exposures through a unified view, thanks to our exposure scoring and AI-enabled recommendations. Get one solution for 360° digital exposure management and visibility across your external attack surface and internal security posture, to proactively prevent cyber-attacks. Elements XM is a bit like pen testing or red teaming, but more continuous and comprehensive of your entire digital environment. WithSecure™ Elements XM uses patent-pending AI-based attack path simulation technologies for heuristic exposure hunting and adversarial exposure validation. The solution is more powerful than traditional vulnerability scanners or vulnerability management software, as it prioritizes your exposures by using AI-powered attack path mapping. In other words, you can remediate exposures through the attacker’s lens. Elements XM discovers exposures for your: - Devices - Digital identities (Entra ID) - Cloud infrastructure (misconfigurations in AWS and Azure cloud) - Networks - External Attack Surface (EASM - External Attack Surface Mapping)

Average Rating: 4.0/5.0

Total Reviews: 1

Who Is the Company Behind WithSecure Elements Exposure Management?

  • Seller: WithSecure
  • Year Founded: 1988
  • HQ Location: Helsinki, Finland
  • Twitter: @WithSecure
    66,501 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,780 employees on LinkedIn®
  • Ownership: FSOYF

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of WithSecure Elements Exposure Management?

What Are G2 Users Discussing About WithSecure Elements Exposure Management?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated April 10, 2026