Best Vulnerability Scanner Software - Page 14

How Many Vulnerability Scanner Software Products Does G2 Track?

Total Products under this Category: 236

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Armis (+0.18%) - Among all products in this category, Armis recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Vulnerability Scanner Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 7,800+ Authentic Reviews
  • 236+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Vulnerability Scanner Software

G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, CrowdStrike Falcon Cloud Security, Orca Security, Tenable Nessus, Astra Pentest, Intruder, and Burp Suite.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=orca-security&focus%5B%5D=tenable-nessus&focus%5B%5D=astra-pentest&focus%5B%5D=intruder&focus%5B%5D=burp-suite)

Nsauditor Network Security Auditor

Nsauditor is a powerful network security auditing tools suite designed for network auditing, network scanning, network monitoring, detecting vulnerabilities and more.

Who Is the Company Behind Nsauditor Network Security Auditor?

N-Stalker

N-Stalker Web Application Security Scanner X is a web security assessment solution for web applications.

Who Is the Company Behind N-Stalker?

  • Seller: N-Stalker
  • Year Founded: 2000
  • HQ Location: Curitiba, BR
  • Twitter: @nstalker
    677 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4 employees on LinkedIn®

Olimpio Security

Olimpio is an external vulnerability scanner built for UK small businesses. It scans your domain for security weaknesses — open ports, missing email authentication records, expired SSL certificates, HTTP security headers, exposed API keys, and known software vulnerabilities — and explains every finding in plain English with clear remediation steps. Most vulnerability scanners are built for enterprise security teams with technical staff to interpret the results. Olimpio is different. Results are explained in plain English so business owners and non-technical managers can understand exactly what is wrong and how to fix it. Key features: external port scanning (standard and deep mode), DNS and email security checks (DMARC, SPF, DKIM), SSL certificate monitoring, HTTP security header analysis, GitHub secrets scanning for exposed API keys, Cyber Essentials control mapping (CE1–CE5), AI-generated plain-English finding explanations, PDF security reports, and security score tracking over time. Free tier available. Starter plan from £49/month.

Who Is the Company Behind Olimpio Security?

On-Premises Scanning

Ostorlab On-Premises Scanning brings AI-powered security testing and Agentic Deep Scans into private environments. Organizations can test private mobile and web applications, APIs, networks, and source code using scanner nodes deployed in their own infrastructure. Staging, development, and restricted systems remain behind existing firewalls or VPN controls, while teams create scans, monitor activity, review findings, and manage remediation through the Ostorlab platform. Extend continuous security testing to private environments without making sensitive systems publicly accessible, while supporting internal security policies and compliance requirements.

Who Is the Company Behind On-Premises Scanning?

  • Seller: Ostorlab
  • Year Founded: 2021
  • HQ Location: Middletown, US
  • Twitter: @OstorlabSec
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

Oversecured

Enterprise vulnerability scanner for Android and iOS apps. It offers app owners and developers the ability to secure each new version of a mobile app by integrating Oversecured into the development process.

Who Is the Company Behind Oversecured?

Oxeye Application Security Platform

Oxeye is an application security solution that was developed to address the unique architecture of cloud native applications. We combine static analysis with runtime flow tracing and infrastructure analysis. Using this multilayered approach, we provide a contextual analysis of vulnerabilities, and prioritize them based on their severity. For greater insights, we report whether third party packages are loaded or not, show infrastructure configuration, and graphically show users the vulnerable flow from the internet to a particular line of code, for quicker remediation. With Oxeye, false positives, and false negatives, become a thing of the past. Installation generally takes less than 5 minutes, and does not require changes to the code or the deployment of any software packages. All that’s required is the deployment of a container within your environment. Once running, Oxeye will automatically scan the environment and provide all of the analysis on its own.

Who Is the Company Behind Oxeye Application Security Platform?

PenScan

PenScan is a security intelligence platform built to help organizations discover vulnerabilities, understand their security exposure, and prioritize the risks that matter most. It gives security teams visibility into weaknesses across their digital assets and helps them focus remediation efforts where they can have the greatest impact. Instead of overwhelming teams with large volumes of security findings, PenScan helps turn vulnerability data into actionable security priorities. Security teams can identify weaknesses, assess their potential impact, and organize remediation efforts based on risk and severity. PenScan is designed for organizations that want a more structured approach to vulnerability discovery and risk management. It supports security teams, IT teams, developers, and organizations working to continuously improve their security posture.

Who Is the Company Behind PenScan?

Quokka Q-mast

Designed for app development, Q-mast embeds security directly into your workflow to identify security, privacy, and compliance risks before the mobile app is released. With a design tailored for DevSecOps workflows, Q-mast supports continuous, automated security testing that aligns with tools like Jenkins, GitLab, and GitHub. Q-mast capabilities: • Automated scanning in minutes, no source code needed • Analysis of compiled app binary, regardless of in-app or run-time obfuscations • Precise SBOM generation and analysis for vulnerability reporting to specific library version, including embedded libraries • Comprehensive static (SAST), dynamic (DAST), interactive (IAST), and forced-path execution app analysis • Malicious behavior profiling, including app collusion • Checks against privacy & security standards: NIAP, NIST, MASVS

Who Is the Company Behind Quokka Q-mast?

Raven.io

Runtime Application Protection | Stop Exploits Before They Run Raven protects applications at runtime — the layer where attacks actually happen. Whether a CVE exists or not. 70% of attacks arrive with no CVE at time of exploitation. WAFs see traffic but not execution. EDR sees processes but not library behavior. SCA catches known CVEs but misses everything else. Traditional security tools are blind to what is actually executing inside your applications — and that is where modern attacks live. Raven closes that gap. Raven gives security teams unprecedented visibility into how applications, libraries, and functions actually behave in production — without code changes, code injection, or application restarts. See exactly which libraries are executing, how they chain together, and whether that behavior is legitimate or malicious. What Raven does: Runtime ADR — Detect and block application-layer attacks including CVE-less exploits, supply chain compromises, and AI-generated threats at the point of execution. Runtime SCA — De-prioritize up to 99% of CVE noise by identifying which vulnerable libraries are actually executing in production versus present but dormant. Runtime AI-DR — Discover, monitor, and control every AI agent operating in your environment. Runtime Gatekeeper — Predict and block dangerous deployments before they reach production. Deployment: Kubernetes-native. Single Helm chart. No code changes. No restarts. Near-zero performance impact. Supports Java, Python, Node.js, Go, Ruby, PHP, and all JVM-based languages. Any cloud. Linux kernel 4.18+.

Who Is the Company Behind Raven.io?

RedHunt Labs ASM Platform

RedHunt Labs is a 360º Attack Surface Management platform that stands out by offering an unparalleled and all-encompassing solution. Our platform goes beyond traditional host and subdomain discovery, extending its reach to encompass a vast array of assets, including third-party SaaS clouds, Docker images, GitHub repositories, Postman collections, and more. With RedHunt Labs ASM Platform, an organization can - continuously track their exposure on the internet - keep an eye on External Supply Chain risks - manage vendor and subsidiary risk - find security issues before threat actors do.

Average Rating: 4.8/5.0

Total Reviews: 6

How Do G2 Users Rate RedHunt Labs ASM Platform?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind RedHunt Labs ASM Platform?

  • Seller: RedHunt Labs
  • Year Founded: 2019
  • HQ Location: London, GB
  • Twitter: @RedHuntLabs
    3,628 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    35 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Small, 33% Large

What Do G2 Reviewers Say About RedHunt Labs ASM Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the real-time risk insights provided by RedHunt Labs ASM, enhancing their security measures effectively.
  • Users value the real-time visibility provided by RedHunt Labs ASM, enhancing their security insights and risk management.
  • Users value the proactive vulnerability identification of RedHunt Labs ASM, enhancing their security posture effectively and efficiently.
  • Users value the actionable intelligence provided by RedHunt Labs ASM Platform, enhancing customization and relevance of data.
  • Users value the alert notifications feature for proactively identifying security risks and safeguarding online assets efficiently.
Cons
  • Users find the dashboard usability issues challenging, wishing for more detailed alerts to assess risks effectively.
  • Users find the inefficient alert system lacking detail, which hinders their understanding of potential risks.
  • Users find the lack of native integrations a limitation, with a desire for better API and Okta SSO support.
  • Users feel the lack of detail in alerts hinders their understanding of risks and affects dashboard usability.
  • Users find the poor usability of RedHunt Labs ASM Platform challenging, especially regarding the dashboard and alerts.

What Are Recent G2 Reviews of RedHunt Labs ASM Platform?

Red Sift ASM

With Red Sift ASM (Attack Surface Management), you can continuously discover, inventory and manage your business’s critical external-facing and cloud assets. With Red Sift ASM, you: 1) Get complete visibility with a view into your entire attack surface – including assets you didn't know existed; 2) Remediate configuration risks before bad actors can take advantage; 3) Reduce premiums by solving problems before they are visible to your cyber insurer.

Average Rating: 4.0/5.0

Total Reviews: 1

Who Is the Company Behind Red Sift ASM?

  • Seller: Red Sift
  • Year Founded: 2015
  • HQ Location: London, England, United Kingdom
  • Twitter: @redsift
    1,267 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    97 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Do G2 Reviewers Say About Red Sift ASM?

AI-generated summary from verified user reviews

Pros
  • Users value the automated asset detection in Red Sift ASM, enhancing their cybersecurity and network monitoring capabilities.
  • Users find the automation for asset detection in Red Sift ASM invaluable for continuous network security monitoring.
  • Users value the automation testing capabilities of Red Sift ASM for robust asset detection and cybersecurity monitoring.
  • Users find the comprehensive monitoring of Red Sift ASM invaluable for automated asset detection and cybersecurity.
  • Users value the automated asset detection capabilities of Red Sift ASM, enhancing cybersecurity through continuous monitoring.

What Are Recent G2 Reviews of Red Sift ASM?

Resecurity Digital Risk Monitoring Platform

Resecurity's Digital Risk Monitoring Platform, Risk™, is an AI-driven solution designed to automate digital risk management by providing actionable intelligence on significant changes to an organization's security posture. It continuously monitors for threats such as data breaches, compromised credentials, network infections, and other security incidents, enabling proactive defense against cyber threats. Key Features and Functionality: - Comprehensive Risk Evaluation: Conducts in-depth assessments across the entire enterprise ecosystem to identify vulnerabilities and security gaps. - Scalable Monitoring: Capable of monitoring digital footprints of any size on a massive scale, ensuring extensive coverage. - Effective Threat Mitigation: Provides early-warning security notifications and automated daily security posture reports to facilitate timely remediation actions. - Risk Measurement: Assigns daily security scores based on monitored domains, IPs, networks, vulnerabilities, and cloud services, offering a clear overview of the organization's security status. - Risk Assessment: Refines and enriches data points to pinpoint weaknesses and vulnerabilities in digital assets, with updates delivered through reports or emails as new data emerges. - Global Visibility: Utilizes geo-location capabilities to deliver contextual information, identifying low, medium, and high-risk areas for managing infrastructure and network resources. Primary Value and Problem Solved: Risk™ empowers organizations to proactively manage and mitigate digital risks by providing real-time insights into their security posture. By automating the detection of external threats—including account takeovers, botnet infections, business email compromises, cyberespionage, brand reputation abuse, dark web activity, domain squatting, data breaches, and more—the platform enables businesses to identify and address vulnerabilities promptly. This proactive approach helps prevent potential security incidents, safeguarding the organization's assets, reputation, and customer trust.

Who Is the Company Behind Resecurity Digital Risk Monitoring Platform?

Rocket z/Assure Vulnerability Analysis Program (VAP)

Elevate your mainframe’s security posture with Rocket® z/Assure VAP, ensuring your system remains resilient against modern threats while optimizing its performance.

Who Is the Company Behind Rocket z/Assure Vulnerability Analysis Program (VAP)?

  • Seller: Rocket Software
  • Year Founded: 1990
  • HQ Location: Waltham, MA
  • Twitter: @Rocket
    3,532 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4,417 employees on LinkedIn®
Lauren Worth
LW
Researched and written by Lauren Worth
Updated April 10, 2026